Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 302 respecto a la semana anterior
Críticas / altas1389▼ 21 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

68 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)1.3%—Yokogawa ExaopcYokogawa ExaplogYokogawa ExaquantumYokogawa Exaquantum/batch+426/12/201917/6/2026
An unquoted search path vulnerability in Multiple Yokogawa products for Windows (Exaopc (R1.01.00 ? R3.77.00), Exaplog (R1.10.00 ? R3.40.00), Exaquantum (R1.10.00 ? R3.02.00 and R3.15.00), Exaquantum/Batch (R1.01.00 ? R2.50.40), Exasmoc (all revisions), Exarqe (all revisions), GA10 (R1.01.01 ? R3.05.01), and…
ModificadaCrítica (9.8)5.4%—Yokogawa B/M 9000 VPYokogawa Centum VPYokogawa PRMYokogawa Prosafe-rs13/2/201917/6/2026
License Manager Service of YOKOGAWA products (CENTUM VP (R5.01.00 - R6.06.00), CENTUM VP Entry Class (R5.01.00 - R6.06.00), ProSafe-RS (R3.01.00 - R4.04.00), PRM (R4.01.00 - R4.02.00), B/M9000 VP(R7.01.01 - R8.02.03)) allows remote attackers to bypass access restriction to send malicious files to the PC where License…
ModificadaAlta (7.5)3.3%—Yokogawa Centum CS 3000 FirmwareYokogawa Centum CS 3000 Entry ClassYokogawa Centum VP FirmwareYokogawa Centum VP Entry Class+59/1/201917/6/2026
Multiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 - R3.09.50), CENTUM CS 3000 Entry Class(R3.05.00 - R3.09.50), CENTUM VP(R4.01.00 - R6.03.10), CENTUM VP Entry Class(R4.01.00 - R6.03.10), Exaopc(R3.10.00 - R3.75.00), PRM(R2.06.00 - R3.31.00), ProSafe-RS(R1.02.00 -…
ModificadaCrítica (9.8)4.0%—Yokogawa Idefine FOR Prosafe-rs FirmwareYokogawa Stardom Versatile Data Server FirmwareYokogawa Stardom Fcn/fcj Simulator FirmwareYokogawa Astplanner+19/1/201917/6/2026
Buffer overflow in the license management function of YOKOGAWA products (iDefine for ProSafe-RS R1.16.3 and earlier, STARDOM VDS R7.50 and earlier, STARDOM FCN/FCJ Simulator R4.20 and earlier, ASTPLANNER R15.01 and earlier, TriFellows V5.04 and earlier) allows remote attackers to stop the license management function…
ModificadaMedia (5.3)1.1%—Yokogawa FCJ FirmwareYokogawa Fcn-100 FirmwareYokogawa Fcn-rtu FirmwareYokogawa Fcn-500 Firmware12/10/201817/6/2026
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The application utilizes multiple methods of session management which could result in a denial of service to the remote management functions.
ModificadaCrítica (9.8)1.9%—Yokogawa FCJ FirmwareYokogawa Fcn-100 FirmwareYokogawa Fcn-rtu FirmwareYokogawa Fcn-500 Firmware12/10/201817/6/2026
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers.
ModificadaAlta (7.5)1.3%—Yokogawa FCJ FirmwareYokogawa Fcn-100 FirmwareYokogawa Fcn-rtu FirmwareYokogawa Fcn-500 Firmware12/10/201817/6/2026
Yokogawa STARDOM Controllers FCJ,FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The controller application fails to prevent memory exhaustion by unauthorized requests. This could allow an attacker to cause the controller to become unstable.
ModificadaAlta (8.1)1.2%—Yokogawa FCJ FirmwareYokogawa Fcn-100 FirmwareYokogawa Fcn-rtu FirmwareYokogawa Fcn-500 Firmware12/10/201817/6/2026
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify information. This attack can be executed only during maintenance work.
ModificadaCrítica (9.8)6.9%—Yokogawa FCJ FirmwareYokogawa Fcn-100 FirmwareYokogawa Fcn-rtu FirmwareYokogawa Fcn-500 Firmware31/7/201817/6/2026
Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and prior, and FCN-500 controllers R4.02 and prior utilize hard-coded credentials that could allow an attacker to gain unauthorized administrative access to the device, which could result in remote code…
ModificadaMedia (6.5)0.29%—Yokogawa B/m9000 CSYokogawa B/m9000 VPYokogawa Centum CS 3000Yokogawa Centum VP+117/4/201817/6/2026
A weakness in access controls in CENTUM CS 1000 all versions, CENTUM CS 3000 versions R3.09.50 and earlier, CENTUM CS 3000 Small versions R3.09.50 and earlier, CENTUM VP versions R6.03.10 and earlier, CENTUM VP Small versions R6.03.10 and earlier, CENTUM VP Basic versions R6.03.10 and earlier, Exaopc versions R3.75.00…
ModificadaAlta (7.3)2.6%—Yokogawa Stardom Fcn/fcj19/9/201617/6/2026
Yokogawa STARDOM FCN/FCJ controller R1.01 through R4.01 does not require authentication for Logic Designer connections, which allows remote attackers to reconfigure the device or cause a denial of service via a (1) stop application program, (2) change value, or (3) modify application command.
ModificadaAlta (7.5)23%—Yokogawa ExaopcYokogawa Centum CS 3000Yokogawa Centum VP22/12/201417/6/2026
BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00 and R5.x through R5.04.00, and Exaopc through R3.72.10, does not require authentication, which allows remote attackers to read arbitrary files via a RETR operation, write to arbitrary files via a…
ModificadaBaja (3.2)0.32%—Yokogawa Fast/tools6/12/201417/6/2026
XML external entity (XXE) vulnerability in the WebHMI server in Yokogawa Electric Corporation FAST/TOOLS before R9.05-SP2 allows local users to cause a denial of service (CPU or network traffic consumption) or read arbitrary files via unspecified vectors.
ModificadaAlta (8.3)62%💥 ExploitYokogawa ExaopcYokogawa B/m9000cs SoftwareYokogawa B/m9000csYokogawa Centum VP Entry Class Software+1110/7/201417/6/2026
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier, when FCS/Test Function is enabled, allows remote attackers to execute…
ModificadaAlta (8.3)57%💥 ExploitYokogawa B/m9000cs SoftwareYokogawa B/m9000csYokogawa Centum CS 1000 SoftwareYokogawa Centum CS 1000+1116/5/201417/6/2026
Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 and earlier, CENTUM VP R5.03.00 and earlier, CENTUM VP Entry Class R5.03.00 and earlier, Exaopc R3.71.02 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP…
ModificadaAlta (8.3)36%💥 ExploitYokogawa Centum CS 300014/3/201417/6/2026
Stack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.
ModificadaAlta (9)68%💥 ExploitYokogawa Centum CS 300014/3/201417/6/2026
Stack-based buffer overflow in BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.
ModificadaAlta (9.3)25%—Yokogawa Centum CS 300014/3/201417/6/2026
Heap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via crafted UDP packets.
Orbitaley — Vulnerabilidades