IM
IronMonkey Threat Research
‹ Back to ICS Advisories

YSAR-23-0002: Affected Yokogawa products by Expat (libexpat) vulnerabilities

UNKNOWN
CVSS 0.0
Date 2026-07-28T15:24:15+00:00
Source yokogawa
Published by Yokogawa

// Description

1 / 2YSAR-23-0002E Yokogawa Security Advisory Report > All Rights Reserved. Copyright © 2023, Yokogawa Electric Corporation # Yokogawa Security Advisory Report ## YSAR-23-0002 Published on October 20, 2023 Last updated on October 20, 2023 YSAR-23-0002: Affected Yokogawa products by Expat (libexpat) vulnerabilities Overview: Yokogawa products that are affected by vulnerabilities in the XML parser library "Expat (libexpat)“ has been found. Yokogawa has identified the range of affe

// Vulnerabilities (2)

CVE ID CVSS Score Severity Description
CVE-2022-40674 0.0 unknown
CVE-2022-40674. Local users can write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.
CVE-2022-43680 0.0 unknown
CVE-2022-43680. In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.

// Affected Products (5)

Vendor Product Asset Type Purdue Level Firmware
Siemens Unknown network_device -- --
Siemens Unknown plc
L1
--
Siemens Unknown plc
L1
--
Siemens Unknown plc
L1
--
Siemens Unknown plc
L1
--

// Remediations (18)

Mitigation: Mitigating factors describe conditions and circumstances that make an attack that exploits the vuln
Mitigating factors describe conditions and circumstances that make an attack that exploits the vulnerability difficult or less likely to succeed. The following mitigations are recommended. 5. Filter specific ICMP packets from external systems (ICMP type 13 and 14) by firewall for not exposing the system time. Refer to section General security recommendations for additional advice on how to keep your system secure.
Patch: Update to V2.2 or later version
Update to V2.2 or later version
Patch: Update to V1.0.3.1 or later version
Update to V1.0.3.1 or later version
Patch: AFS660/665S, AFS660/665C, AFS670v2: Apply mitigation strategy as described in General Mitigation Fac
AFS660/665S, AFS660/665C, AFS670v2: Apply mitigation strategy as described in General Mitigation Factors Section or update to upcoming 7.1.08 when available.
Patch: Do not use process control systems for internet surfing, instant messaging, or receiving emails.
Do not use process control systems for internet surfing, instant messaging, or receiving emails.
Patch: Hitachi Energy also recommends general mitigations:
Hitachi Energy also recommends general mitigations:
Patch: Scan portable computers and removable storage media for malware prior connection to a control system
Scan portable computers and removable storage media for malware prior connection to a control system.
Patch: AFS670/675, AFR67x: Apply mitigation strategy as described in General Mitigation Factors Section or
AFS670/675, AFR67x: Apply mitigation strategy as described in General Mitigation Factors Section or update to 9.1.08.
Patch: AFS65x: EoL product - only mitigation available, no remediation expected. Apply mitigation strategy
AFS65x: EoL product - only mitigation available, no remediation expected. Apply mitigation strategy as described in General Mitigation Factors Section.
Patch: Recommended security practices and firewall configurations can help protect a process control networ
Recommended security practices and firewall configurations can help protect a process control network from attacks originating from outside the network.
Patch: Ensure process control systems have no direct connections to the internet and are separated from oth
Ensure process control systems have no direct connections to the internet and are separated from other networks by a firewall system with a minimal number of exposed ports.
Patch: Physically protect process control systems from direct access by unauthorized personnel.
Physically protect process control systems from direct access by unauthorized personnel.
Patch: For more information, see Hitachi Energy�s Security Advisory: 8DBD000149.
For more information, see Hitachi Energy�s Security Advisory: 8DBD000149.
Patch: Hitachi Energy has released the following mitigations/fixes:
Hitachi Energy has released the following mitigations/fixes:
Patch: AFF660/665: Apply mitigation strategy as described in General Mitigation Factors Section or update t
AFF660/665: Apply mitigation strategy as described in General Mitigation Factors Section or update to upcoming release.
Patch: Update to V3.1.5 or later version
Update to V3.1.5 or later version
Mitigation: Only build and run applications from trusted sources.
Only build and run applications from trusted sources.
Mitigation: Mitigating factors describe conditions and circumstances that make an attack that exploits the vuln
Mitigating factors describe conditions and circumstances that make an attack that exploits the vulnerability difficult or less likely to succeed. The following mitigations are recommended. 5. Filter specific ICMP packets from external systems (ICMP type 13 and 14) by firewall for not exposing the system time. Refer to section General security recommendations for additional advice on how to keep your system secure.

// References