Path traversal in Yokogawa products - CVE-2022-21808

 

Path traversal in Yokogawa products - CVE-2022-21808

Published: March 29, 2022


Vulnerability identifier: #VU61676
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21808
CWE-ID: CWE-22
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker on the local network can send a specially crafted packet to a CAMS for HIS server and read and write arbitrary files on the system.


Affected software

CENTUM VP Entry Class
CENTUM CS 3000 Entry Class
CENTUM VP
CENTUM CS 3000
Exaopc

How to mitigate CVE-2022-21808

Install updates from vendor's website.

CENTUM VP Entry Class - update to R6.09
CENTUM VP - update to R6.09
Exaopc - update to R3.80

External References

Related Security Bulletins