VDB
ICSA-22-123-01
ICSA-22-123-01
PUBLISHED
CVSS 8.600000381469727 HIGH
Successful exploitation of these vulnerabilities may allow leakage/tampering of data, cause a denial-of-service condition, or allow a local attacker to execute arbitrary programs.
Risk Scores
CVSS 4.0
8.600000381469727
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| B/M9000 VP: R6.01.01 through R6.03.02 | ||
| CENTUM VP (Including CENTUM VP Entry Class): R6.01.10 through R6.09.00 - (if VP6E5000 is installed) | ||
| Prosafe-RS: R4.01.00 through R4.07.00 - if RS4E5000 is installed | ||
| Prosafe-RS: R4.01.00 through R4.05.00 - if RS4E5000 or RS4E5100 are installed | ||
| B/M9000 VP: R8.01.01 through R8.03.01 | ||
| CENTUM VP (Including CENTUM VP Entry Class): R6.01.10 through R6.07.10 - if VP6E5000 or VP6E5100 are installed |
Timeline
- May 3, 2022 CVE Published
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-22-123-01 advisory
- https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01 url
- https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B url
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2022/icsa-22-123-01.json advisory
- https://www.cisa.gov/uscert/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf url
- https://contact.yokogawa.com/cs/gw?c-id=000498 fix