#VU61677 Improper Authentication in Yokogawa products - CVE-2022-22729
Published: March 29, 2022
Vulnerability identifier: #VU61677
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-22729
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
CENTUM VP
CENTUM CS 3000
Exaopc
CENTUM CS 3000 Entry Class
CENTUM VP Entry Class
CENTUM VP
CENTUM CS 3000
Exaopc
CENTUM CS 3000 Entry Class
CENTUM VP Entry Class
Software vendor:
Yokogawa
Yokogawa
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to CAMS for HIS Server improperly authenticate the receiving packets. A remote user can bypass authentication process and gain unauthorized access to the application.
Remediation
Install updates from vendor's website.