CVE-2020-5609

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
05/08/2020
Last modified:
12/08/2020

Description

Directory traversal vulnerability in CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R8.03.01 allows a remote unauthenticated attacker to create or overwrite arbitrary files and run arbitrary commands via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:yokogawa:centum_cs_3000_firmware:*:*:*:*:*:*:*:* r3.08.10 (including) r3.09.50 (including)
cpe:2.3:h:yokogawa:centum_cs_3000:-:*:*:*:*:*:*:*
cpe:2.3:o:yokogawa:centum_vp_firmware:*:*:*:*:*:*:*:* r4.01.00 (including) r4.03.00 (including)
cpe:2.3:o:yokogawa:centum_vp_firmware:*:*:*:*:*:*:*:* r5.01.00 (including) r5.04.20 (including)
cpe:2.3:o:yokogawa:centum_vp_firmware:*:*:*:*:*:*:*:* r6.01.00 (including) r6.07.00 (including)
cpe:2.3:h:yokogawa:centum_vp:-:*:*:*:*:*:*:*
cpe:2.3:o:yokogawa:b\/m9000cs_firmware:*:*:*:*:*:*:*:* r5.04.01 (including) r5.05.01 (including)
cpe:2.3:h:yokogawa:b\/m9000cs:-:*:*:*:*:*:*:*
cpe:2.3:o:yokogawa:b\/m9000vp_firmware:*:*:*:*:*:*:*:* r6.01.01 (including) r8.03.01 (including)
cpe:2.3:h:yokogawa:b\/m9000vp:-:*:*:*:*:*:*:*