CVE Database
/

CVE-2024-5650

Back to search

CVE-2024-5650

Published: Jun 17, 2024

Modified: Aug 1, 2024

PUBLISHED

CVSS v3.1

8.5

HIGH

Description

DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an attacker is somehow able to intrude into a computer that installed affected product or access to a shared folder, by replacing the DLL file with a tampered one, it is possible to execute arbitrary programs with the authority of the SYSTEM account. The affected products and versions are as follows: CENTUM CS 3000 R3.08.10 to R3.09.50 CENTUM VP R4.01.00 to R4.03.00, R5.01.00 to R5.04.20, R6.01.00 to R6.11.10.

VendorProductVersions

Yokogawa Electric Corporation

CENTUM CS 3000

affected
R3.08.10 - <= R3.09.50

Yokogawa Electric Corporation

CENTUM VP

affected
R4.01.00 - <= R4.03.00
affected
R5.01.00 - <= R5.04.20
affected
R6.01.00 - <= R6.11.10

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

High

Privileges Required

Low

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now