Vulnerabilidades em Yokogawa Electric Corporation

53 resultados
Análise Vexday

Com 53 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o perfil de risco da Yokogawa Electric Corporation situa-se abaixo da média geral do catálogo, o que indica uma superfície de exposição operacional relativamente contida no momento. A falha mais comum é classificada como CWE-358, relacionada a implementações inadequadas de mecanismos de segurança, padrão que merece atenção em ambientes de tecnologia operacional onde controles de autenticação e autorização são críticos. A CVE mais perigosa ativa atualmente, CVE-2019-5909, apresenta EPSS de 0,0541, sem PoC pública disponível, sugerindo risco de exploração ainda limitado, embora sua antiguidade indique que correções devem ter sido priorizadas há tempo. O surgimento de uma nova CVE nos últimos 90 dias reforça a necessidade de monitoramento contínuo, especialmente em infraestruturas industriais onde janelas de patching são tipicamente mais restritas.

CVE-2022-27188OS command injection vulnerability exists in CENTUM VP R4.01.00 to R4.03.00, CENTUM VP Small R4.01.00 to R4.03.00, CENTUM VP Basic R4.01.00 EPSS 0.5%CVE-2024-4105MEDIUMA vulnerability has been found in FAST/TOOLS and CI Server. The affected product's WEB HMI server's function to process HTTP requests has a EPSS 0.5%CVE-2024-8110HIGHDenial of Service (DoS) vulnerability has been found in Dual-redundant Platform for Computer. If a computer on which the affected product isEPSS 0.4%CVE-2024-4106MEDIUMA vulnerability has been found in FAST/TOOLS and CI Server. The affected products have built-in accounts with no passwords set. Therefore, iEPSS 0.4%CVE-2025-66608HIGHA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate URLs. An EPSS 0.4%CVE-2022-29519Cleartext transmission of sensitive information vulnerability exists in STARDOM FCN Controller and FCJ Controller R1.01 to R4.31, which may EPSS 0.4%CVE-2024-5650HIGHDLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an attacker is somehow abEPSS 0.3%CVE-2025-66600HIGHA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product lacks HSTS (HTTP Strict Transport SeEPSS 0.3%CVE-2025-66602MEDIUMA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts access by IP address. WhenEPSS 0.3%CVE-2025-66599MEDIUMA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Physical paths could be displayed on web pages. TEPSS 0.3%CVE-2025-66603LOWA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts the OPTIONS method. An attEPSS 0.3%CVE-2025-48020MEDIUMA vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciouEPSS 0.2%CVE-2022-23401The following Yokogawa Electric products contain insecure DLL loading issues. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP vEPSS 0.2%CVE-2022-22148'Root Service' service implemented in the following Yokogawa Electric products creates some named pipe with improper ACL configuration. CENTEPSS 0.2%CVE-2026-11833HIGHOverview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing the CI Server settingEPSS 0.2%CVE-2025-66606LOWA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly encode URLs. An atEPSS 0.2%CVE-2025-48019MEDIUMA vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciouEPSS 0.2%CVE-2022-22141'Long-term Data Archive Package' service implemented in the following Yokogawa Electric products creates some named pipe with imporper ACL cEPSS 0.2%CVE-2025-66594MEDIUMA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Detailed messages are displayed on the error page. EPSS 0.2%CVE-2025-1924MEDIUMA vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receive maliciousEPSS 0.2%