Description
CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R8.03.01 allows a remote unauthenticated attacker to bypass authentication and send altered communication packets via unspecified vectors.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://web-material3.yokogawa.com/1/29820/files/YSAR-20-0001-E.pdf
Third Party Advisory x_refsource_misc
https://jvn.jp/vu/JVNVU97997181/index.html
Scores
CVSS v3
9.8
EPSS
0.0159
EPSS Percentile
72.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-287
Status
published
Products (4)
yokogawa/b\/m9000cs_firmware
r5.04.01 - r5.05.01
yokogawa/b\/m9000vp_firmware
r6.01.01 - r8.03.01
yokogawa/centum_cs_3000_firmware
r3.08.10 - r3.09.50
yokogawa/centum_vp_firmware
r4.01.00 - r4.03.00
Published
Aug 05, 2020
Tracked Since
Feb 18, 2026