CVE-2018-16196 is a denial-of-service vulnerability affecting multiple Yokogawa products, including various versions of CENTUM CS 3000, CENTUM VP, Exaopc, PRM, ProSafe-RS, FAST/TOOLS, and B/M9000 VP. This flaw allows remote attackers to disrupt the Vnet/IP Open Communication Driver's communication through unspecified vectors. With a CVSS score of 7.5 (High), it presents a significant risk due to its network-based attack vector and low attack complexity, potentially leading to a complete loss of availability. There is no evidence of active exploitation, nor are public exploit tools like Metasploit or ExploitDB available. Despite limited community discussion, the vulnerability has received media coverage, indicating some awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= r3.05.00, <= r3.09.50CPE matchmatch criteria | cpe:2.3:o:yokogawa:centum_cs_3000_firmware:*:*:*:*:*:*:*:* | ||
>= r3.05.00, <= r3.09.50CPE matchmatch criteria | cpe:2.3:a:yokogawa:centum_cs_3000_entry_class:*:*:*:*:*:*:*:* | ||
>= r4.01.00, <= r6.03.10CPE matchmatch criteria | cpe:2.3:o:yokogawa:centum_vp_firmware:*:*:*:*:*:*:*:* | ||
>= r4.01.00, <= r6.03.10CPE matchmatch criteria | cpe:2.3:a:yokogawa:centum_vp_entry_class:*:*:*:*:*:*:*:* | ||
>= r6.03.01, <= r8.01.90CPE matchmatch criteria | cpe:2.3:a:yokogawa:b\/m9000_vp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.