6.5
CVE-2018-8838
- EPSS 0.06%
- Published 17.04.2018 21:29:00
- Last modified 21.11.2024 04:14:25
- Source ics-cert@hq.dhs.gov
- Teams watchlist Login
- Open Login
A weakness in access controls in CENTUM CS 1000 all versions, CENTUM CS 3000 versions R3.09.50 and earlier, CENTUM CS 3000 Small versions R3.09.50 and earlier, CENTUM VP versions R6.03.10 and earlier, CENTUM VP Small versions R6.03.10 and earlier, CENTUM VP Basic versions R6.03.10 and earlier, Exaopc versions R3.75.00 and earlier, B/M9000 CS all versions, and B/M9000 VP versions R8.01.01 and earlier may allow a local attacker to exploit the message management function of the system. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H).
Data is provided by the National Vulnerability Database (NVD)
Yokogawa ≫ B/m9000 Cs Version-
Yokogawa ≫ B/m9000 Vp Version <= r8.01.01
Yokogawa ≫ Centum Cs 3000 Version <= r3.09.50
Yokogawa ≫ Centum Cs 3000 SwEditionsmall Version <= r3.09.50
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.06% | 0.165 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 1 | 5.5 |
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H
|
nvd@nist.gov | 4.4 | 3.4 | 6.4 |
AV:L/AC:M/Au:N/C:P/I:P/A:P
|