CVE-2018-17900

CRITICAL

Yokogawa STARDOM Controllers FCJ FCN-100 FCN-RTU FCN-500 < R4.10 - Insufficiently Protected Credentials

Title source: llm
STIX 2.1

Description

Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://web-material3.yokogawa.com/YSAR-18-0007-E.pdf
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03

Scores

CVSS v3 9.8
EPSS 0.0186
EPSS Percentile 76.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-522
Status published
Products (4)
yokogawa/fcj_firmware < r4.10
yokogawa/fcn-100_firmware < r4.10
yokogawa/fcn-500_firmware < r4.10
yokogawa/fcn-rtu_firmware < r4.10
Published Oct 12, 2018
Tracked Since Feb 18, 2026