CVE-2022-21194

CRITICAL

Yokogawa CENTUM VP R5.01.00-R5.04.20 and R6.01.00-R6.08.00 and Exaopc R3.72.00-R3.79.00 - Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Description

The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.0, Exaopc versions from R3.72.00 to R3.79.00.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0093
EPSS Percentile 55.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (3)
yokogawa/centum_vp_entry_firmware r4.01.00 - r4.03.00
yokogawa/centum_vp_firmware r5.01.00 - r5.04.20
yokogawa/exaopc r3.72.00 - r3.80.00
Published Mar 11, 2022
Tracked Since Feb 18, 2026