CVE-2018-8838
A weakness in access controls in CENTUM CS 1000 all versions, CENTUM CS 3000 versions R3.09.50 and earlier, CENTUM CS 3000 Small versions R3.09.50 and earlier, CENTUM VP versions R6.03.10 and earlier, CENTUM VP Small versions R6.03.10 and earlier, CENTUM VP Basic versions R6.03.10 and earlier, Exaopc versions R3.75.00 and earlier, B/M9000 CS all versions, and B/M9000 VP versions R8.01.01 and earlier may allow a local attacker to exploit the message management function of the system. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H).
Published:Apr 17, 2018
Last Modified:Nov 21, 2024
EPS:Apr 17, 2018
EPSS Score:0.00063
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Yokogawa
Product
B\/m9000 Cs
Yokogawa
B\/m9000 Cs
Vendor
Yokogawa
Product
B\/m9000 Vp
Yokogawa
B\/m9000 Vp
Vendor
Yokogawa
Product
Centum Cs 3000
Yokogawa
Centum Cs 3000
Vendor
Yokogawa
Product
Centum Vp
Yokogawa
Centum Vp
Vendor
Yokogawa
Product
Exaopc
Yokogawa
Exaopc
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
