CVE-2018-17900

CRITICAL

Yokogawa STARDOM - Info Disclosure

Title source: llm

Description

Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers.

Scores

CVSS v3 9.8
EPSS 0.0026
EPSS Percentile 49.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-522
Status published

Affected Products (4)

yokogawa/fcj_firmware < r4.10
yokogawa/fcn-100_firmware < r4.10
yokogawa/fcn-rtu_firmware < r4.10
yokogawa/fcn-500_firmware < r4.10

Timeline

Published Oct 12, 2018
Tracked Since Feb 18, 2026