Insecure DLL loading in Yokogawa products - CVE-2022-23401

 

Insecure DLL loading in Yokogawa products - CVE-2022-23401

Published: March 29, 2022


Vulnerability identifier: #VU61684
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23401
CWE-ID: CWE-427
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to the application loads DLL libraries in an insecure manner. A remote attacker on the local network can place a specially crafted .dll file and execute arbitrary code on victim's system.


Affected software

CENTUM VP Entry Class
CENTUM CS 3000 Entry Class
CENTUM VP
CENTUM CS 3000
Exaopc

How to mitigate CVE-2022-23401

Install updates from vendor's website.

CENTUM VP Entry Class - update to R6.09
CENTUM VP - update to R6.09
Exaopc - update to R3.80

External References

Related Security Bulletins