CVE-2014-3888

UnknownEPSS 62.31%

Last modified

CVE-2014-3888 is a vulnerability of currently unknown severity. Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier, when FCS/Test Function is enabled, allows remote attackers to execute arbitrary code via a crafted packet.. EPSS estimates a 62.31% chance of exploitation in the next 30 days.

Description

Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier, when FCS/Test Function is enabled, allows remote attackers to execute arbitrary code via a crafted packet.

Metrics

EPSS Probability
62.31%

99.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
YokogawaExaopc<= 3.72.00
YokogawaExaopc3.71.02
YokogawaB\/M9000cs Software<= 5.05.01
YokogawaB\/M9000csAll versions
YokogawaCentum Vp Entry Class Software<= 5.03.00
YokogawaCentum Vp Entry ClassAll versions
YokogawaCentum Vp Software<= 5.03.20
YokogawaCentum Vp Software4.03.00
YokogawaCentum VpAll versions
YokogawaB\/M9000 Vp Software<= 7.03.01
YokogawaB\/M9000 VpAll versions
YokogawaCentum Cs 3000 Software<= 2.23.00
YokogawaCentum Cs 3000All versions
YokogawaCentum Cs 1000 SoftwareAll versions
YokogawaCentum Cs 1000All versions
YokogawaCentum Cs 3000 Entry Class Software<= 3.09.50
YokogawaCentum Cs 3000 Entry ClassAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-3888?
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier, when FCS/Test Function is enabled, allows remote attackers to execute arbitrary code via a crafted packet.
How severe is CVE-2014-3888?
Severity scoring for CVE-2014-3888 is pending analysis. The EPSS model estimates a 62.31% probability of exploitation in the next 30 days.
How do I fix CVE-2014-3888?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-3888?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST