IM
IronMonkey Threat Research
‹ Back to ICS Advisories

YSAR-22-0007: Vulnerabilities in STARDOM

MEDIUM
CVSS 6.3
Date 2026-07-28T15:24:28+00:00
Source yokogawa
Published by Yokogawa

// Description

1 / 2YSAR-22-0007-E Yokogawa Security Advisory Report > All Rights Reserved. Copyright © 2022, Yokogawa Electric Corporation # Yokogawa Security Advisory Report # YSAR-22-0007 Published on June 21, 2022 Last updated on June 29, 2022 ## YSAR-22-0007: Vulnerabilities in STARDOM Overview: Vulnerabilities have been found in STARDOM. Yokogawa has identified the range of affected products in this report. Review the report and confirm which products are affected to implement security

// Vulnerabilities (2)

CVE ID CVSS Score Severity Description
CVE-2022-29519 6.3 medium
The affected product transmits sensitive information in cleartext, which may allow an attacker sniffing network traffic on the controller to read/change configuration settings or update the controller with tampered firmware.CVE-2022-29519 has been assigned to this vulnerability. A CVSS v3 base score of 4.8 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).
CVE-2022-30997 6.3 medium
The affected product uses hard-coded credentials, which could enable an attacker to read/change configuration settings or update the controller with tampered firmware. Note, single CPU modules of the FCN/FCJ controller are unaffected.CVE-2022-30997 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).

// Remediations (5)

Mitigation: See Yokogawa's security advisory report YSAR-22-007 for more information.
See Yokogawa's security advisory report YSAR-22-007 for more information.
Mitigation: Ensure network traffic cannot be captured by unauthorized users.
Ensure network traffic cannot be captured by unauthorized users.
Mitigation: Yokogawa considers patching to be the best mitigation against these vulnerabilities. Users are encou
Yokogawa considers patching to be the best mitigation against these vulnerabilities. Users are encouraged to contact Yokogawa to discuss the best course of action for individual systems.
Mitigation: Yokogawa strongly recommends users establish and maintain an operational security program, including
Yokogawa strongly recommends users establish and maintain an operational security program, including regular patching, anti-virus, backup and recovery processes, network segmentation, hardened networks, whitelisting, firewalls, etc. Yokogawa can assist users in setting up and maintaining these security programs, including performing an initial security risk assessment.
Mitigation: Enable the packet filtering functionality of the FCN/FCJ controller to only allow connections from t
Enable the packet filtering functionality of the FCN/FCJ controller to only allow connections from trusted hosts.

// References