CVE-2022-27188
HIGHYokogawa CENTUM VP and B/M9000 VP - OS Command Injection via Graphic Builder File Alteration
Title source: llmDescription
OS command injection vulnerability exists in CENTUM VP R4.01.00 to R4.03.00, CENTUM VP Small R4.01.00 to R4.03.00, CENTUM VP Basic R4.01.00 to R4.03.00, and B/M9000 VP R6.01.01 to R6.03.02, which may allow an attacker who can access the computer where the affected product is installed to execute an arbitrary OS command by altering a file generated using Graphic Builder.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://www.yokogawa.com/library/resources/white-papers/yokogawa-security-advisory-report-list/
Third Party Advisory x_refsource_misc
https://jvn.jp/vu/JVNVU99204686/index.html
Scores
CVSS v3
7.8
EPSS
0.0050
EPSS Percentile
38.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (2)
yokogawa/b\/m9000_vp
r6.01.01 - r6.03.02
yokogawa/centum_vp
r4.01.00 - r4.03.00 (3 CPE variants)
Published
Apr 15, 2022
Tracked Since
Feb 18, 2026