CVE-2022-29519

HIGH

Yokogawa STARDOM FCN and FCJ Firmware R1.01-R4.31 - Cleartext Transmission of Sensitive Information

Title source: llm
STIX 2.1

Description

Cleartext transmission of sensitive information vulnerability exists in STARDOM FCN Controller and FCJ Controller R1.01 to R4.31, which may allow an adjacent attacker to login the affected products and alter device configuration settings or tamper with device firmware.

References (4)

Core 4
Core References
Mitigation, Vendor Advisory x_refsource_misc
https://web-material3.yokogawa.com/1/32885/files/YSAR-22-0007-E.pdf
Mitigation, Vendor Advisory x_refsource_misc
https://web-material3.yokogawa.com/19/32885/files/YSAR-22-0007-J.pdf
Mitigation, Third Party Advisory, VDB Entry x_refsource_misc
https://jvn.jp/vu/JVNVU95452299/index.html
Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-01

Scores

CVSS v3 7.5
EPSS 0.0036
EPSS Percentile 27.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-319
Status published
Products (2)
yokogawa/stardom_fcj_firmware r1.01 - r4.31
yokogawa/stardom_fcn_firmware r1.01 - r4.31
Published Jun 28, 2022
Tracked Since Feb 18, 2026