header-logo
Suggest Exploit
vendor:
Yokogawa Centum CS3000
by:
Redsadic, juan vazquez
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Yokogawa Centum CS3000
Affected Version From: Yokogawa Centum CS3000 R3.08.50
Affected Version To: Yokogawa Centum CS3000 R3.08.50
Patch Exists: NO
Related CWE: CVE-2014-3888
CPE: a:yokogawa:centum_cs3000:r3.08.50
Metasploit:
Other Scripts:
Platforms Tested: Windows
2014

Yokogawa CS3000 BKFSim_vhfd.exe Buffer Overflow

This module exploits a stack based buffer overflow on Yokogawa CS3000. The vulnerability exists in the service BKFSim_vhfd.exe when using malicious user-controlled data to create logs using functions like vsprintf and memcpy in an insecure way. This module has been tested successfully on Yokogawa Centum CS3000 R3.08.50 over Windows XP SP3.

Mitigation:

Upgrade to a version of Yokogawa CS3000 that does not have this vulnerability. Apply security patches provided by the vendor.
Source

Exploit-DB raw data: