CVE-2022-27188

HIGH

Yokogawa CENTUM VP and B/M9000 VP - OS Command Injection via Graphic Builder File Alteration

Title source: llm
STIX 2.1

Description

OS command injection vulnerability exists in CENTUM VP R4.01.00 to R4.03.00, CENTUM VP Small R4.01.00 to R4.03.00, CENTUM VP Basic R4.01.00 to R4.03.00, and B/M9000 VP R6.01.01 to R6.03.02, which may allow an attacker who can access the computer where the affected product is installed to execute an arbitrary OS command by altering a file generated using Graphic Builder.

References (2)

Core 2

Scores

CVSS v3 7.8
EPSS 0.0050
EPSS Percentile 38.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (2)
yokogawa/b\/m9000_vp r6.01.01 - r6.03.02
yokogawa/centum_vp r4.01.00 - r4.03.00 (3 CPE variants)
Published Apr 15, 2022
Tracked Since Feb 18, 2026