ICSA-22-174-02
·
Published 2022-06-23
·
View on CISA ICS-CERT ↗
Yokogawa CAMS for HIS
CVSS 6.4
MEDIUM
Risk Summary
If a computer using CAMS for HIS software is compromised, it can be used to compromise any number of other computers using CAMS for HIS software with the potential to crash any affected software.
CVEs (1)
Remediations
- CENTUM CS 3000 (Including CENTUM CS 3000 Entry Class): No software patch will be made available as these products are end-of-life. Upgrade systems to the latest version of CENTUM VP.
- Versions R4.01.00 through R4.03.00, and R5.01.00 through R5.04.20: No software patch will be made available as these products are end-of-life. Consider upgrading systems to the latest version of CENTUM VP.
- Versions R6.01.00 through R6.09.00: Update systems to Version R6.09.00 and apply software patch R6.09.03
- Exaopc: Update systems to Version R3.80.00 and apply software patch R3.80.01
- B/M9000CS and B/M9000 VP: These products are not directly affected by the vulnerability. However, these products are affected if CENTUM is installed on the same PC. If CENTUM is installed, update as described above. Also update B/M9000 to the latest version.
- Please see Yokogawa Security Advisory Report YSAR-22-0006 at the following locations for more information: English
- Please see Yokogawa Security Advisory Report YSAR-22-0006 at the following locations for more information: Japanese
- For questions related to these mitigations, please contact Yokogawa.
Affected Vendors
Yokogawa
Affected Products (5)
Yokogawa
·
B/M9000 VP
>= R6.01.01 | <= R8.03.01
Yokogawa
·
B/M9000CS
>= R5.04.01 | <= R5.05.01
Yokogawa
·
CENTUM CS 3000 (including CENTUM CS 3000 Entry Class)
>= R3.08.10 | <= R3.09.00. | LHS4800 (CAMS for HIS) is installed.
Yokogawa
·
CENTUM VP (including CENTUM VP Entry Class)
>= R4.01.00 | <= R4.03.00 (these product versions are affected only if CAMS function is used) Versions R5.01.00 through R5.04.20 and R6.01.00 through R6.09.00 (these product versions are affected regardless of whether CAMS function is used or not)
Yokogawa
·
Exaopc
>= R3.72.00 | <= R3.80.00 (these product versions are affected if NTPF100-S6 "For CENTUM VP Support CAMS for HIS" is installed)
Affected Sectors
Critical Manufacturing, Energy, Food and Agriculture
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more