First published: Wed Aug 05 2020(Updated: )
CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R8.03.01 allows a remote unauthenticated attacker to bypass authentication and send altered communication packets via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Yokogawa Centum Cs 3000 Firmware | >=r3.08.10<=r3.09.50 | |
Yokogawa CENTUM CS 3000 | ||
Yokogawa Centum Vp Firmware | >=r4.01.00<=r4.03.00 | |
Yokogawa Centum Vp Firmware | >=r5.01.00<=r5.04.20 | |
Yokogawa Centum Vp Firmware | >=r6.01.00<=r6.07.00 | |
Yokogawa Centum Vp | ||
Yokogawa B\/m9000cs Firmware | >=r5.04.01<=r5.05.01 | |
Yokogawa B\/m9000cs | ||
Yokogawa B\/m9000vp Firmware | >=r6.01.01<=r8.03.01 | |
Yokogawa B\/m9000vp |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5608 is a vulnerability in CAMS for HIS CENTUM CS 3000, CENTUM VP, B/M9000CS, and B/M9000VP.
CVE-2020-5608 has a severity score of 9.8 (Critical).
CAMS for HIS CENTUM CS 3000 (R3.08.10 to R3.09.50), CENTUM VP (R4.01.00 to R6.07.00), B/M9000CS (R5.04.01 to R5.05.01), and B/M9000VP (R6.01.01 to R8.03.01) are affected.
A remote unauthenticated attacker can exploit CVE-2020-5608 to bypass authentication and send altered commands.
You can find more information about CVE-2020-5608 at the following references: [link1](https://jvn.jp/vu/JVNVU97997181/index.html), [link2](https://web-material3.yokogawa.com/1/29820/files/YSAR-20-0001-E.pdf).