CVE-2014-3888 is a stack-based buffer overflow in the BKFSim_vhfd.exe component of several Yokogawa CENTUM and B/M9000 industrial control systems, as well as Exaopc, when the FCS/Test Function is enabled. This vulnerability allows unauthenticated remote attackers to execute arbitrary code by sending a specially crafted packet. With a CVSS score of 8.3 (High), it presents a significant risk due to its network-based attack vector, medium attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. Exploit code is publicly available via a Metasploit module, though there is no evidence of active exploitation in the wild, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.72.00CPE matchmatch criteria | cpe:2.3:a:yokogawa:exaopc:*:*:*:*:*:*:*:* | ||
3.71.02CPE matchmatch criteria | cpe:2.3:a:yokogawa:exaopc:3.71.02:*:*:*:*:*:*:* | ||
<= 5.05.01CPE matchmatch criteria | cpe:2.3:a:yokogawa:b\/m9000cs_software:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:yokogawa:b\/m9000cs:-:*:*:*:*:*:*:* | ||
<= 5.03.00CPE matchmatch criteria | cpe:2.3:a:yokogawa:centum_vp_entry_class_software:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.