CRITICAL · 9.8

CVE-2015-5626

Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP E...

Vulnerability Description

Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and earlier, Exapilot R3.96.10 and earlier, Exaplog R3.40.00 and earlier, Exasmoc R4.03.20 and earlier, Exarqe R4.03.20 and earlier, Field Wireless Device OPC Server R2.01.02 and earlier, PRM R3.12.00 and earlier, STARDOM VDS R7.30.01 and earlier, STARDOM OPC Server for Windows R3.40 and earlier, FAST/TOOLS R10.01 and earlier, B/M9000CS R5.05.01 and earlier, B/M9000 VP R7.03.04 and earlier, and FieldMate R1.01 or R1.02 allows remote attackers to cause a denial of service (network-communications outage) via a crafted packet.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
YokogawaCentum Cs 1000 Firmware<= r3.08.70
YokogawaCentum Cs 1000-
YokogawaCentum Cs 3000 Firmware<= r3.09.50
YokogawaCentum Cs 3000-
YokogawaCentum Cs 3000 Entry Firmware<= r3.09.50
YokogawaCentum Cs 3000 Entry-
YokogawaCentum Vp Firmware<= r5.04.20
YokogawaCentum Vp-
YokogawaCentum Vp Entry Firmware<= r5.04.20
YokogawaCentum Vp Entry-
YokogawaProsafe-Rs Firmware<= r3.02.10
YokogawaProsafe-Rs-
YokogawaExaopc<= r3.72.00
YokogawaExapilot<= r3.96.10
YokogawaExaplog<= r3.40.00
YokogawaExaquantum<= r2.85.00
YokogawaExaquantum\/Batch<= r2.50.30
YokogawaExarqe<= r4.03.20
YokogawaExasmoc<= r4.03.20
YokogawaField Wireless Device Opc Server<= r2.01.02

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-5626?

CVE-2015-5626 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP E...

How severe is CVE-2015-5626?

CVE-2015-5626 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2015-5626?

Check the references section above for vendor advisories and patch information. Affected products include: Yokogawa Centum Cs 1000 Firmware, Yokogawa Centum Cs 1000, Yokogawa Centum Cs 3000 Firmware, Yokogawa Centum Cs 3000, Yokogawa Centum Cs 3000 Entry Firmware.