CVE-2022-27188
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
15/04/2022
Last modified:
22/04/2022
Description
OS command injection vulnerability exists in CENTUM VP R4.01.00 to R4.03.00, CENTUM VP Small R4.01.00 to R4.03.00, CENTUM VP Basic R4.01.00 to R4.03.00, and B/M9000 VP R6.01.01 to R6.03.02, which may allow an attacker who can access the computer where the affected product is installed to execute an arbitrary OS command by altering a file generated using Graphic Builder.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
4.40
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:yokogawa:b\/m9000_vp:*:*:*:*:*:*:*:* | r6.01.01 (including) | r6.03.02 (including) |
| cpe:2.3:a:yokogawa:centum_vp:*:*:*:*:-:*:*:* | r4.01.00 (including) | r4.03.00 (including) |
| cpe:2.3:a:yokogawa:centum_vp:*:*:*:*:basic:*:*:* | r4.01.00 (including) | r4.03.00 (including) |
| cpe:2.3:a:yokogawa:centum_vp:*:*:*:*:small:*:*:* | r4.01.00 (including) | r4.03.00 (including) |
To consult the complete list of CPE names with products and versions, see this page



