Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Yokogawa Group

First CVE: Mar 14, 2014Active for: 12 yearsTotal CVEs: 63
45.0
VTI Score
High

Yokogawa Group is among the more prominent operators of industrial control and process-automation software, with a well-represented vulnerability footprint spanning supervisory control platforms, middleware, and firmware across its CENTUM and EXAOPC product lines. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the high-value nature of these systems and their exposure to network-based attack. The durable exposure concentrates in flagship products such as CENTUM VP and CENTUM CS 3000—along with their associated firmware—and recurs through memory-safety weaknesses including buffer overflows and out-of-bounds writes, authentication and credential-handling flaws, and path-traversal conditions that are characteristic of large industrial software with complex networking and management interfaces. Defenders deploying Yokogawa platforms should prioritize these advisories for internal threat modeling and treat internet-facing instances with particular caution; live severity, exploitation, and exposure figures are shown alongside this summary.

FAUCET AI Generated
63
Total CVEs
More Total CVEs than 99% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Yokogawa Group over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2014
12 years ago
Most Recent CVE
Feb 13, 2026
163 days ago

Self-Reporting Analysis

Of all the CVEs published by Yokogawa Group as a CNA, 69.0% affect products that Yokogawa Group develops as a vendor.

69.0%
31.0%
Self-reported: 20 (69.0%)
Third-party: 9 (31.0%)

Of all the CVEs published that affect products developed by Yokogawa Group, 31.7% are self-published by Yokogawa Group as a CNA.

31.7%
68.3%
Self-published: 20 (31.7%)
Other CNAs: 43 (68.3%)

Products(89 total)

Top CVEs

Signals from CVEs in this vendor scope (63 CVEs).

63 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-0783HIGH
Stack-based buffer overflow in BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.
Mar 14, 20149.077NOYES
CVE-2014-3888HIGH
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000
Jul 10, 20148.375NOYES
CVE-2014-0782HIGH
Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 and earlier, CENTUM VP R5.03.00
May 16, 20148.370NOYES
CVE-2014-0784HIGH
Stack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.
Mar 14, 20148.358NOYES
CVE-2014-5208HIGH
BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00 and R5.x through R5.04.00, and Exaopc through R3.72.10, doe
Dec 22, 20147.547NOYES
CVE-2014-0781HIGH
Heap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via crafted UDP packets.
Mar 14, 20149.346NOYES
CVE-2018-10592CRITICAL
Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and prior, and FCN-500 controllers R4.02 and prior utilize hard-cod
Jul 31, 20189.832NONO
CVE-2022-23402CRITICAL
The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.00, E
Mar 11, 20229.831NONO
CVE-2022-21194CRITICAL
The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 a
Mar 11, 20229.831NONO
CVE-2020-5608CRITICAL
CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01,
Aug 5, 20209.831NONO
View all 63 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products63 CVEs
24%
48%
27%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local7 (11.1%)
Network41 (65.1%)
Unknown7 (11.1%)
Physical0 (0.0%)
Adjacent Network8 (12.7%)
Attack Complexity
Low53 (84.1%)
High3 (4.8%)
Unknown7 (11.1%)
User Interaction
None50 (79.4%)
Unknown7 (11.1%)
Required6 (9.5%)
Privileges Required
Low10 (15.9%)
High1 (1.6%)
None45 (71.4%)
Unknown7 (11.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (63 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
6 CVEs
9.5% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
6.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Yokogawa Group.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Yokogawa Group — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Yokogawa Group's Products

View all 4 CNAs →

Top CWEs