CVE-2014-3888

high
Published 2014-07-10 · Modified 2026-05-06
CVSS v3
CVSS v2
8.3
VIR risk
8.3

Description

Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier, when FCS/Test Function is enabled, allows remote attackers to execute arbitrary code via a crafted packet.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: vultures@jpcert.or.jp — http://www.yokogawa.com/dcs/security/ysar/YSAR-14-0002E.pdf

Application impact

VendorProductVersionsFixed
yokogawaexaopc{"endIncluding":"3.72.00"}
yokogawaexaopc3.71.02
yokogawab\/m9000cs_software{"endIncluding":"5.05.01"}
yokogawacentum_vp_entry_class_software{"endIncluding":"5.03.00"}
yokogawacentum_vp_software{"endIncluding":"5.03.20"}
yokogawacentum_vp_software4.03.00
yokogawab\/m9000_vp_software{"endIncluding":"7.03.01"}
yokogawacentum_cs_3000r3.01
yokogawacentum_cs_3000r3.02
yokogawacentum_cs_3000r3.03
yokogawacentum_cs_3000r3.04
yokogawacentum_cs_3000r3.05
yokogawacentum_cs_3000r3.06
yokogawacentum_cs_3000r3.07
yokogawacentum_cs_3000r3.08
yokogawacentum_cs_3000r3.08.50
yokogawacentum_cs_3000r3.08.70
yokogawacentum_cs_3000r3.09
yokogawacentum_cs_3000r3.09.50
yokogawacentum_cs_3000_software{"endIncluding":"2.23.00"}
yokogawacentum_cs_1000_software-
yokogawacentum_cs_3000_entry_class_software{"endIncluding":"3.09.50"}

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.