CVE-2024-5650
HIGHYokogawa Electric Corporation - CENTUM CAMS Log server - DLL Hijacking
Title source: llmDescription
DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an attacker is somehow able to intrude into a computer that installed affected product or access to a shared folder, by replacing the DLL file with a tampered one, it is possible to execute arbitrary programs with the authority of the SYSTEM account. The affected products and versions are as follows: CENTUM CS 3000 R3.08.10 to R3.09.50 CENTUM VP R4.01.00 to R4.03.00, R5.01.00 to R5.04.20, R6.01.00 to R6.11.10.
References (1)
Core 1
Core References
Various Sources vendor-advisory
https://web-material3.yokogawa.com/1/36044/files/YSAR-24-0002-E.pdf
Scores
CVSS v3
8.5
EPSS
0.0034
EPSS Percentile
25.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-284
Status
published
Products (4)
Yokogawa Electric Corporation/CENTUM CS 3000
R3.08.10 - R3.09.50
Yokogawa Electric Corporation/CENTUM VP
R4.01.00 - R4.03.00
Yokogawa Electric Corporation/CENTUM VP
R5.01.00 - R5.04.20
Yokogawa Electric Corporation/CENTUM VP
R6.01.00 - R6.11.10
Published
Jun 17, 2024
Tracked Since
Feb 18, 2026