Resource exhaustion in Yokogawa products - CVE-2022-22145
Published: March 29, 2022
Vulnerability identifier: #VU61680
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22145
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in CAMS for HIS Log Server. A remote user can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
CENTUM VP Entry Class
CENTUM CS 3000 Entry Class
CENTUM VP
CENTUM CS 3000
Exaopc
CENTUM CS 3000 Entry Class
CENTUM VP
CENTUM CS 3000
Exaopc
How to mitigate CVE-2022-22145
Install updates from vendor's website.
CENTUM VP Entry Class - update to R6.09
CENTUM VP - update to R6.09
Exaopc - update to R3.80
CENTUM VP - update to R6.09
Exaopc - update to R3.80