← Back to home
ICSA-23-334-02  ·  Published 2023-11-30  ·  View on CISA ICS-CERT ↗

Yokogawa STARDOM

CVSS 5.3 MEDIUM

Risk Summary

Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service condition to the FCN/FCJ controller by sending a specially crafted packet.

CVEs (1)

Remediations

  • Yokogawa has released the following mitigations for users to implement:
  • By using the packet filter function of the FCN/FCJ controller, only allow connection from trusted hosts. Revision up FCN/FCJ basic software to R4.20 or later for using the function.
  • Take measures against the network so that an attacker cannot send a malicious packet
  • Yokogawa strongly recommends all customers to establish and maintain a full security program, not only for the vulnerability identified in this YSAR. Security program components are: Patch updates, Anti-virus, Backup and recovery, zoning, hardening, whitelisting, firewall, etc. Yokogawa can assist in setting up and running the security program continuously. For considering the most effective risk mitigation plan, as a starting point, Yokogawa can perform a security risk assessment.
  • More details can also be found in Yokogawa's security advisory report number YSAR-23-0003.

Affected Vendors

Yokogawa

Affected Products (1)

Yokogawa · STARDOM FCN/FCJ >=R1.01|<=R4.31

Affected Sectors

Multiple

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more