IM
IronMonkey Threat Research
‹ Back to ICS Advisories

YSAR-22-0008: Denial of Service (DoS) vulnerability in CENTUM controller FCS

MEDIUM
CVSS 6.5
Date 2026-07-28T15:24:23+00:00
Source yokogawa
Published by Yokogawa

// Description

1 / 2YSAR-22-0008-E Yokogawa Security Advisory Report > All Rights Reserved. Copyright © 2022, Yokogawa Electric Corporation # Yokogawa Security Advisory Report ## YSAR-22-0008 Published on July 29, 2022 Last updated on July 29, 2022 YSAR-22-0008: Denial of Service (DoS) vulnerability in CENTUM controller FCS Overview: Denial of Service (DoS) vulnerability has been found in CENTUM controller FCS. Yokogawa has identified the range of affected products in this report. Review the

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2022-33939 6.5 medium
The Yokogawa CENTUM VP/CS 3000 Controller FCS is vulnerable to a denial-of-service attack caused by a malformed packet. This attack may stop inter-station data link block (ADL) communications.CVE-2022-33939 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been assigned; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

// Affected Products (1)

Vendor Product Asset Type Purdue Level Firmware
Yokogawa Unknown dcs
L2
CP31 | CP33 | CP345

// Remediations (7)

Mitigation: Yokogawa has listed the following products as vulnerable due to end-of-life status with no software
Yokogawa has listed the following products as vulnerable due to end-of-life status with no software patch available: CENTUM CS 3000
Mitigation: Yokogawa has provided software patches for the following vulnerable products: CENTUM VP Entry Class
Yokogawa has provided software patches for the following vulnerable products: CENTUM VP Entry Class (R6.01.00 to R6.03.00)
Mitigation: For more information and details on implementing these mitigations and downloading the latest patch,
For more information and details on implementing these mitigations and downloading the latest patch, users should see the Yokogawa advisory.
Mitigation: Yokogawa has listed the following products as vulnerable due to end-of-life status with no software
Yokogawa has listed the following products as vulnerable due to end-of-life status with no software patch available: CENTUM VP (R4.01.00 to R4.03.00)
Mitigation: Yokogawa has provided software patches for the following vulnerable products: CENTUM VP (R5.01.00 to
Yokogawa has provided software patches for the following vulnerable products: CENTUM VP (R5.01.00 to R5.04.20)
Mitigation: Yokogawa has listed the following products as vulnerable due to end-of-life status with no software
Yokogawa has listed the following products as vulnerable due to end-of-life status with no software patch available: CENTUM CS 3000 Entry Class
Mitigation: Yokogawa has listed the following products as vulnerable due to end-of-life status with no software
Yokogawa has listed the following products as vulnerable due to end-of-life status with no software patch available: CENTUM VP Entry Class (R4.01.00 to R4.03.00)

// References