| CVE ID | CVSS Score | Severity | Description |
|---|---|---|---|
| CVE-2024-4106 | 5.8 | medium |
The affected products have built-in accounts with no passwords set. Therefore, if the product is operated without a password set by default, an attacker can break into the affected product.
|
| CVE-2024-4105 | 5.8 | medium |
The affected product's WEB HMI server's function to process HTTP requests has a security flaw (reflected XSS) that allows the execution of malicious scripts. Therefore, if a client PC with inadequate security measures accesses a product URL containing a malicious request, the malicious script may be executed on the client PC.
|
| Vendor | Product | Asset Type | Purdue Level | Firmware |
|---|---|---|---|---|
| Yokogawa | Unknown | hmi |
L2
|
-- |
| Yokogawa | Unknown | hmi |
L2
|
-- |