CVE-2014-0784

Yokogawa CENTUM CS 3000 < R3.09.50 - Remote Code Execution via Crafted TCP Packet

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2014-0784. PoCs published by Metasploit, juan vazquez, including Metasploit module exploits/windows/scada/yokogawa_bkbcopyd_bof.

AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in Yokogawa CENTUM CS 3000's BKBCopyD.exe service via a crafted RETR command. It achieves remote code execution by overwriting the return address and executing shellcode.

Description

Stack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/32210

This Metasploit module exploits a stack-based buffer overflow in Yokogawa CENTUM CS 3000's BKBCopyD.exe service via a crafted RETR command. It achieves remote code execution by overwriting the return address and executing shellcode.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Yokogawa CENTUM CS 3000 R3.08.50
No auth needed
Prerequisites: Network access to port 20111 · Target running vulnerable Yokogawa CENTUM CS 3000 version
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/scada/yokogawa_bkbcopyd_bof.rb

This Metasploit module exploits a stack-based buffer overflow in Yokogawa CENTUM CS 3000's BKBCopyD.exe service via a crafted RETR command. It targets Windows XP SP3 with a specific return address to achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Yokogawa CENTUM CS 3000 R3.08.50
No auth needed
Prerequisites: Network access to port 20111 · Vulnerable version of Yokogawa CENTUM CS 3000
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6

Scores

EPSS 0.3604
EPSS Percentile 98.3%

Details

CWE
CWE-119 CWE-121
Status published
Products (13)
Yokogawa/CENTUM CS 3000 < R3.09.50
yokogawa/centum_cs_3000 r3.01
yokogawa/centum_cs_3000 r3.02
yokogawa/centum_cs_3000 r3.03
yokogawa/centum_cs_3000 r3.04
yokogawa/centum_cs_3000 r3.05
yokogawa/centum_cs_3000 r3.06
yokogawa/centum_cs_3000 r3.07
yokogawa/centum_cs_3000 r3.08
yokogawa/centum_cs_3000 r3.08.50
... and 3 more
Published Mar 14, 2014
Tracked Since Feb 18, 2026