First published: Thu Jul 10 2014(Updated: )
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier, when FCS/Test Function is enabled, allows remote attackers to execute arbitrary code via a crafted packet.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Yokogawa Exaopc | <=3.72.00 | |
Yokogawa Exaopc | =3.71.02 | |
Yokogawa B\/m9000cs Software | <=5.05.01 | |
Yokogawa B\/m9000cs | ||
Yokogawa Centum Vp Entry Class Software | <=5.03.00 | |
Yokogawa Centum Vp Entry Class | ||
Yokogawa Centum Vp Software | <=5.03.20 | |
Yokogawa Centum Vp Software | =4.03.00 | |
Yokogawa Centum Vp | ||
Yokogawa B\/m9000 Vp Software | <=7.03.01 | |
Yokogawa B\/m9000 Vp | ||
Yokogawa CENTUM CS 3000 | =r3.01 | |
Yokogawa CENTUM CS 3000 | =r3.02 | |
Yokogawa CENTUM CS 3000 | =r3.03 | |
Yokogawa CENTUM CS 3000 | =r3.04 | |
Yokogawa CENTUM CS 3000 | =r3.05 | |
Yokogawa CENTUM CS 3000 | =r3.06 | |
Yokogawa CENTUM CS 3000 | =r3.07 | |
Yokogawa CENTUM CS 3000 | =r3.08 | |
Yokogawa CENTUM CS 3000 | =r3.08.50 | |
Yokogawa CENTUM CS 3000 | =r3.08.70 | |
Yokogawa CENTUM CS 3000 | =r3.09 | |
Yokogawa CENTUM CS 3000 | =r3.09.50 | |
Yokogawa Centum Cs 3000 Software | <=2.23.00 | |
Yokogawa CENTUM CS 3000 | ||
Yokogawa Centum Cs 1000 Software | ||
Yokogawa CENTUM CS 1000 | ||
Yokogawa Centum Cs 3000 Entry Class Software | <=3.09.50 | |
Yokogawa Centum Cs 3000 Entry Class |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-3888 is considered critical due to its potential to allow remote code execution via a stack-based buffer overflow.
To fix CVE-2014-3888, you should update affected software to the latest versions that address the vulnerability as specified by Yokogawa.
CVE-2014-3888 affects Yokogawa CENTUM CS 1000, CENTUM CS 3000, CENTUM VP, Exaopc, and B/M9000 software prior to their respective patched versions.
CVE-2014-3888 is caused by a stack-based buffer overflow in BKFSim_vhfd.exe when the FCS/Test Function is enabled.
Yes, CVE-2014-3888 can be exploited by remote attackers to execute arbitrary code on the affected systems.