Yokogawa Group is among the more prominent operators of industrial control and process-automation software, with a well-represented vulnerability footprint spanning supervisory control platforms, middleware, and firmware across its CENTUM and EXAOPC product lines. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the high-value nature of these systems and their exposure to network-based attack. The durable exposure concentrates in flagship products such as CENTUM VP and CENTUM CS 3000—along with their associated firmware—and recurs through memory-safety weaknesses including buffer overflows and out-of-bounds writes, authentication and credential-handling flaws, and path-traversal conditions that are characteristic of large industrial software with complex networking and management interfaces. Defenders deploying Yokogawa platforms should prioritize these advisories for internal threat modeling and treat internet-facing instances with particular caution; live severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yokogawa Group over time
Of all the CVEs published by Yokogawa Group as a CNA, 69.0% affect products that Yokogawa Group develops as a vendor.
Of all the CVEs published that affect products developed by Yokogawa Group, 31.7% are self-published by Yokogawa Group as a CNA.
Signals from CVEs in this vendor scope (63 CVEs).
63 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0783HIGH Stack-based buffer overflow in BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet. | Mar 14, 2014 | 9.0 | 77 | NO | YES |
CVE-2014-3888HIGH Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000 | Jul 10, 2014 | 8.3 | 75 | NO | YES |
CVE-2014-0782HIGH Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 and earlier, CENTUM VP R5.03.00 | May 16, 2014 | 8.3 | 70 | NO | YES |
CVE-2014-0784HIGH Stack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet. | Mar 14, 2014 | 8.3 | 58 | NO | YES |
CVE-2014-5208HIGH BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00 and R5.x through R5.04.00, and Exaopc through R3.72.10, doe | Dec 22, 2014 | 7.5 | 47 | NO | YES |
CVE-2014-0781HIGH Heap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via crafted UDP packets. | Mar 14, 2014 | 9.3 | 46 | NO | YES |
CVE-2018-10592CRITICAL Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and prior, and FCN-500 controllers R4.02 and prior utilize hard-cod | Jul 31, 2018 | 9.8 | 32 | NO | NO |
CVE-2022-23402CRITICAL The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.00, E | Mar 11, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-21194CRITICAL The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 a | Mar 11, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-5608CRITICAL CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01, | Aug 5, 2020 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (63 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yokogawa Group.
Media articles that mention a CVE ID that affects a product developed by Yokogawa Group — matched by CVE ID, not by vendor name.