Use of hard-coded credentials in Yokogawa products - CVE-2022-23402

 

Use of hard-coded credentials in Yokogawa products - CVE-2022-23402

Published: March 29, 2022


Vulnerability identifier: #VU61674
CSH Severity: Low
CVSS v4: 5.9 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23402
CWE-ID: CWE-798
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain full access to vulnerable system.

The vulnerability exists due to presence of hard-coded credentials in application code within the CAMS server application. A remote unauthenticated attacker on the local network can access the affected system using the hard-coded credentials.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

CENTUM VP Entry Class
CENTUM CS 3000 Entry Class
CENTUM VP
CENTUM CS 3000
Exaopc

How to mitigate CVE-2022-23402

Install updates from vendor's website.

CENTUM VP Entry Class - update to R6.09
CENTUM VP - update to R6.09
Exaopc - update to R3.80

External References

Related Security Bulletins