5.3

CVE-2024-4106

A vulnerability has been found in FAST/TOOLS and CI Server. The affected products have built-in accounts with no passwords set. Therefore, if the product is operated without a password set by default, an attacker can break into the affected product.
The affected products and versions are as follows:
FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04
CI Server R1.01.00 to R1.03.00
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstelleryokogawa_electric_corporation
Produkt fast_tools
Default Statusunknown
Version <= R10.04
Version r901
Status affected
Herstelleryokogawa_electric_corporation
Produkt ci_server
Default Statusunknown
Version <= R1.03.00
Version r1.01.00
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.309
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
7168b535-132a-4efe-a076-338f829b2eb9 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-258 Empty Password in Configuration File

Using an empty string as a password is insecure.

https://web-material3.yokogawa.com/1/36059/files/YSAR-24-0001-E.pdf