CVE-2016-4860 describes an authentication bypass vulnerability in Yokogawa STARDOM FCN/FCJ controllers (R1.01 through R4.01). This flaw allows unauthenticated remote attackers to reconfigure devices or cause a denial of service by issuing commands like stopping application programs, changing values, or modifying applications. With a CVSS score of 7.3 (High), this vulnerability is easily exploitable over the network with low complexity, potentially leading to limited confidentiality, integrity, and availability impacts. While no public exploit code or active exploitation has been confirmed, it has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
r1.01CPE matchmatch criteria | cpe:2.3:a:yokogawa:stardom_fcn\/fcj:r1.01:*:*:*:*:*:*:* | ||
r2.01CPE matchmatch criteria | cpe:2.3:a:yokogawa:stardom_fcn\/fcj:r2.01:*:*:*:*:*:*:* | ||
r3.01CPE matchmatch criteria | cpe:2.3:a:yokogawa:stardom_fcn\/fcj:r3.01:*:*:*:*:*:*:* | ||
r4.01CPE matchmatch criteria | cpe:2.3:a:yokogawa:stardom_fcn\/fcj:r4.01:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.