#VU61684 Insecure DLL loading in Yokogawa products - CVE-2022-23401
Published: March 29, 2022
Vulnerability identifier: #VU61684
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-23401
CWE-ID: CWE-427
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerable software:
CENTUM VP
CENTUM CS 3000
Exaopc
CENTUM CS 3000 Entry Class
CENTUM VP Entry Class
CENTUM VP
CENTUM CS 3000
Exaopc
CENTUM CS 3000 Entry Class
CENTUM VP Entry Class
Software vendor:
Yokogawa
Yokogawa
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to the application loads DLL libraries in an insecure manner. A remote attacker on the local network can place a specially crafted .dll file and execute arbitrary code on victim's system.
Remediation
Install updates from vendor's website.