ID

VAR-202203-0852


CVE

CVE-2022-22151


TITLE

Yokogawa Exaopc Security hole

Trust: 0.6

sources: CNNVD: CNNVD-202203-1150

DESCRIPTION

CAMS for HIS Log Server contained in the following Yokogawa Electric products fails to properly neutralize log outputs: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, and Exaopc versions from R3.72.00 to R3.79.00

Trust: 0.99

sources: NVD: CVE-2022-22151 // VULHUB: VHN-414060

AFFECTED PRODUCTS

vendor:yokogawamodel:centum vp entryscope:gteversion:r5.01.00

Trust: 1.0

vendor:yokogawamodel:centum vpscope:gteversion:r4.01.00

Trust: 1.0

vendor:yokogawamodel:centum cs 3000 entryscope:lteversion:r3.09.00

Trust: 1.0

vendor:yokogawamodel:exaopcscope:ltversion:r3.80.00

Trust: 1.0

vendor:yokogawamodel:exaopcscope:gteversion:r3.72.00

Trust: 1.0

vendor:yokogawamodel:centum cs 3000 entryscope:gteversion:r3.08.10

Trust: 1.0

vendor:yokogawamodel:centum vp entryscope:gteversion:r4.01.00

Trust: 1.0

vendor:yokogawamodel:centum vp entryscope:lteversion:r5.04.20

Trust: 1.0

vendor:yokogawamodel:centum vpscope:lteversion:r5.04.20

Trust: 1.0

vendor:yokogawamodel:centum cs 3000scope:lteversion:r3.09.00

Trust: 1.0

vendor:yokogawamodel:centum vpscope:ltversion:r6.09.00

Trust: 1.0

vendor:yokogawamodel:centum vpscope:lteversion:r4.03.00

Trust: 1.0

vendor:yokogawamodel:centum vp entryscope:lteversion:r4.03.00

Trust: 1.0

vendor:yokogawamodel:centum vp entryscope:gteversion:r6.01.00

Trust: 1.0

vendor:yokogawamodel:centum vpscope:gteversion:r6.01.00

Trust: 1.0

vendor:yokogawamodel:centum cs 3000scope:gteversion:r3.08.10

Trust: 1.0

vendor:yokogawamodel:centum vp entryscope:ltversion:r6.09.00

Trust: 1.0

vendor:yokogawamodel:centum vpscope:gteversion:r5.01.00

Trust: 1.0

sources: NVD: CVE-2022-22151

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-22151
value: HIGH

Trust: 1.0

CNNVD: CNNVD-202203-1150
value: HIGH

Trust: 0.6

VULHUB: VHN-414060
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2022-22151
severity: MEDIUM
baseScore: 4.9
vectorString: AV:N/AC:M/AU:S/C:N/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 6.8
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-414060
severity: MEDIUM
baseScore: 4.9
vectorString: AV:N/AC:M/AU:S/C:N/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 6.8
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2022-22151
baseSeverity: HIGH
baseScore: 8.1
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.2
version: 3.1

Trust: 1.0

sources: VULHUB: VHN-414060 // CNNVD: CNNVD-202203-1150 // NVD: CVE-2022-22151

PROBLEMTYPE DATA

problemtype:CWE-116

Trust: 1.1

problemtype:CWE-117

Trust: 1.0

sources: VULHUB: VHN-414060 // NVD: CVE-2022-22151

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202203-1150

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202203-1150

PATCH

title:Yokogawa Exaopc Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=186332

Trust: 0.6

sources: CNNVD: CNNVD-202203-1150

EXTERNAL IDS

db:NVDid:CVE-2022-22151

Trust: 1.7

db:CS-HELPid:SB2022032906

Trust: 0.6

db:AUSCERTid:ESB-2022.1276

Trust: 0.6

db:ICS CERTid:ICSA-22-083-01

Trust: 0.6

db:CNNVDid:CNNVD-202203-1150

Trust: 0.6

db:VULHUBid:VHN-414060

Trust: 0.1

sources: VULHUB: VHN-414060 // CNNVD: CNNVD-202203-1150 // NVD: CVE-2022-22151

REFERENCES

url:https://web-material3.yokogawa.com/1/32094/files/ysar-22-0001-e.pdf

Trust: 1.7

url:https://www.cybersecurity-help.cz/vdb/sb2022032906

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.1276

Trust: 0.6

url:https://cxsecurity.com/cveshow/cve-2022-22151/

Trust: 0.6

url:https://us-cert.cisa.gov/ics/advisories/icsa-22-083-01

Trust: 0.6

sources: VULHUB: VHN-414060 // CNNVD: CNNVD-202203-1150 // NVD: CVE-2022-22151

CREDITS

Jacob Baines from Dragos reported these vulnerabilities to Yokogawa.

Trust: 0.6

sources: CNNVD: CNNVD-202203-1150

SOURCES

db:VULHUBid:VHN-414060
db:CNNVDid:CNNVD-202203-1150
db:NVDid:CVE-2022-22151

LAST UPDATE DATE

2024-11-23T21:32:45.589000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-414060date:2022-03-18T00:00:00
db:CNNVDid:CNNVD-202203-1150date:2022-03-30T00:00:00
db:NVDid:CVE-2022-22151date:2024-11-21T06:46:15.690

SOURCES RELEASE DATE

db:VULHUBid:VHN-414060date:2022-03-11T00:00:00
db:CNNVDid:CNNVD-202203-1150date:2022-03-11T00:00:00
db:NVDid:CVE-2022-22151date:2022-03-11T09:15:11.627