CVE-2022-27188 PUBLISHED CVSS 7.800000190734863 HIGH

OS command injection vulnerability exists in CENTUM VP R4.01.00 to R4.03.00, CENTUM VP Small R4.01.00 to R4.03.00, CENTUM VP Basic R4.01.00 to R4.03.00, and B/M9000 VP R6.01.01 to R6.03.02, which may allow an attacker who can access the computer where the affected product is installed to execute an arbitrary OS command by altering a file generated using Graphic Builder.

EPSS 0.54% · 67.5th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.54%
67.5th percentile

Affected Products

VendorProductVersions
Yokogawa Electric CorporationCENTUM VP series with VP6E5150(Graphic Builder) installed and B/M9000 VPCENTUM VP R4.01.00 to R4.03.00, CENTUM VP Small R4.01.00 to R4.03.00, CENTUM VP Basic R4.01.00 to R4.03.00, and B/M9000 VP R6.01.01 to R6.03.02
yokogawacentum_vpr4.01.00, r4.01.00, r4.01.00
yokogawab\/m9000_vpr6.01.01

Timeline

References

Open in Interactive Console →