ICSA-22-123-01
·
Published 2022-05-03
·
View on CISA ICS-CERT ↗
Yokogawa CENTUM and ProSafe-RS
CVSS 7.5
HIGH
Risk Summary
Successful exploitation of these vulnerabilities may allow leakage/tampering of data, cause a denial-of-service condition, or allow a local attacker to execute arbitrary programs.
Remediations
- Users of CENTUM Versions R6.01.10 through R6.09.00: Update to R6.09.00 and apply patch software (R6.09.04). In an environment where the AD server and Plant Resource Manager (PRM) are linked, there are some precautions to be taken when applying patch software (R6.09.04). Please be sure to check R6.09.04 install manual for details before applying R6.09.04
- Users of CENTUM Versions R4.01.00 though R4.03.00: No patch software will be available because these products are no longer supported by the vendor.
- B/M9000 VP: This product is not affected by these vulnerabilities. However, this product is affected by the existence of CENTUM installed on the same PC. If CENTUM is installed, perform update, and update B/M9000 to suitable revision.
- Users of Prosafe-RS: Update to R4.07.02 or later
- The environment where both CENTUM VP and ProSafe-RS are installed.
- The environment where CENTUM VP's AD server and PRM are linked.
- The environment where ProSafe-RS's AD server and PRM are linked.
- Contact Yokogawa support for more mitigation information.
- For more information see Yokogawa security advisory report: YSAR-22-0004
Affected Vendors
Yokogawa
Affected Products (6)
Yokogawa
·
B/M9000 VP
>= R6.01.01 | <= R6.03.02
Yokogawa
·
B/M9000 VP
>= R8.01.01 | <= R8.03.01
Yokogawa
·
CENTUM VP (Including CENTUM VP Entry Class)
>= R6.01.10 | <= R6.09.00 - (if VP6E5000 is installed)
Yokogawa
·
CENTUM VP (Including CENTUM VP Entry Class)
>= R6.01.10 | <= R6.07.10 (if P6E5000 or P6E5100 are installed)
Yokogawa
·
Prosafe-RS
>= R4.01.00 | <= R4.07.00 (if RS4E5000 is installed)
Yokogawa
·
Prosafe-RS
>= R4.01.00 | <= R4.05.00 (if RS4E5000 or RS4E5100 are installed)
Affected Sectors
Critical Manufacturing, Energy, Food and Agriculture
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more