Path traversal in Yokogawa products - CVE-2022-21808
Published: March 29, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker on the local network can send a specially crafted packet to a CAMS for HIS server and read and write arbitrary files on the system.
Affected software
CENTUM CS 3000 Entry Class
CENTUM VP
CENTUM CS 3000
Exaopc
How to mitigate CVE-2022-21808
CENTUM VP - update to R6.09
Exaopc - update to R3.80