CVE Vulnerabilities

CVE-2022-26034

Improper Authentication

Published: Apr 15, 2022 | Modified: Apr 22, 2022
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Improper authentication vulnerability in the communication protocol provided by AD (Automation Design) server of CENTUM VP R6.01.10 to R6.09.00, CENTUM VP Small R6.01.10 to R6.09.00, CENTUM VP Basic R6.01.10 to R6.09.00, and B/M9000 VP R8.01.01 to R8.03.01 allows an attacker to use the functions provided by AD server. This may lead to leakage or tampering of data managed by AD server.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
B/m9000_vp Yokogawa r8.01.01 (including) r8.03.01 (including)
Centum_vp Yokogawa r6.01.10 (including) r6.09.00 (including)
Centum_vp Yokogawa r6.01.10 (including) r06.09.00 (including)

Potential Mitigations

References