10

CVE-2019-5909

License Manager Service of YOKOGAWA products (CENTUM VP (R5.01.00 - R6.06.00), CENTUM VP Entry Class (R5.01.00 - R6.06.00), ProSafe-RS (R3.01.00 - R4.04.00), PRM (R4.01.00 - R4.02.00), B/M9000 VP(R7.01.01 - R8.02.03)) allows remote attackers to bypass access restriction to send malicious files to the PC where License Manager Service runs via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
YokogawaB/m 9000 Vp Version >= r7.01.01 <= r8.02.03
YokogawaCentum Vp Version >= r5.01.00 <= r6.06.00
YokogawaCentum Vp SwEditionbasic Version >= r5.01.00 <= r6.06.00
YokogawaCentum Vp SwEditionsmall Version >= r5.01.00 <= r6.06.00
YokogawaPrm Version >= r4.01.00 <= r4.02.00
YokogawaProsafe-rs Version >= r3.01.00 <= r4.04.00
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.41% 0.917
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://jvn.jp/vu/JVNVU99147082/index.html
Third Party Advisory
http://www.securityfocus.com/bid/106772
Third Party Advisory
VDB Entry
https://web-material3.yokogawa.com/1/20653/files/YSAR-19-0001-E.pdf
Vendor Advisory