← Vulnerability feed

Vulnerability record · CVE-2014-0782 · published 16 May 2014

CVE-2014-0782: Yokogawa CENTUM and related products stack buffer overflow in BKESimmgr.exe

Yokogawa · B\/M9000cs Software

BKESimmgr.exe in the Expanded Test Functions package of multiple Yokogawa DCS products contains a stack-based buffer overflow (CWE-121) reachable via a crafted packet. Successful exploitation allows remote code execution on control-system hosts, which matters because these are industrial control systems where a compromise can affect process availability and integrity.

8.3 CVSS 2.0 High EPSS 57% · top 1.0% CWE-121 · Stack-based buffer overflowCWE-119 · Memory buffer overflow
8.3CVSS 2.0 base score
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
15Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 and earlier, CENTUM VP R5.03.00 and earlier, CENTUM VP Entry Class R5.03.00 and earlier, Exaopc R3.71.02 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier allows remote attackers to execute arbitrary code via a crafted packet.

AV:N/AC:M/Au:N/C:P/I:P/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote, unauthenticated code execution in industrial control systems with a high EPSS score and public exploit discussion warrants high priority despite no KEV listing.

What it is

BKESimmgr.exe in the Expanded Test Functions package of multiple Yokogawa DCS products contains a stack-based buffer overflow (CWE-121) reachable via a crafted packet. Successful exploitation allows remote code execution on control-system hosts, which matters because these are industrial control systems where a compromise can affect process availability and integrity.

Impact

A remote attacker can execute arbitrary code with the privileges of the affected process, potentially taking control of the DCS node. The CVSS 2.0 vector indicates partial confidentiality and integrity impact with complete availability impact.

Attack surface

The flaw is network-reachable (AV:N) and requires no authentication (Au:N), though the CVSS vector notes medium access complexity (AC:M). No user interaction is indicated in the record.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS 30-day probability is 0.56839 (99th percentile), indicating high predicted likelihood, and references include a Metasploit community blog post, suggesting public exploit tooling may exist.

What to do

  • Apply the vendor fix per Yokogawa advisory YSAR-14-0001E and confirm affected CENTUM, Exaopc and B/M9000 versions are upgraded.
  • Isolate DCS and control-network segments from business networks and restrict access to the Expanded Test Functions service.
  • Filter or block crafted packets to BKESimmgr.exe using ICS-aware firewalls or network segmentation controls.
  • Monitor Yokogawa and CISA ICS advisories for updated guidance and any revised affected-version lists.

Detection

  • Monitor for unexpected crashes or restarts of BKESimmgr.exe on CENTUM, Exaopc and B/M9000 hosts.
  • Inspect network traffic to the Expanded Test Functions service for malformed or oversized packets.
  • Alert on unusual child processes or command execution originating from BKESimmgr.exe.
  • Review host logs for anomalous activity on DCS nodes around the time of service restarts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-0782 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2022-26034Yokogawa b\/m9000 vp improper authentication vulnerabilityImproper authentication vulnerability in the communication protocol provided by AD (Automation Design) server of CENTUM VP R6.01.10 to R6.09.00, CENT…EPSS 0.98%8.8CVE-2022-30707Yokogawa centum cs 3000 firmware vulnerabilityViolation of secure design principles exists in the communication of CAMS for HIS. Affected products and versions are CENTUM series where LHS4800 is …EPSS 0.58%8.3CVE-2014-3888Yokogawa CENTUM BKFSim_vhfd.exe stack buffer overflowBKFSim_vhfd.exe, a component of Yokogawa CENTUM CS 1000/CS 3000, CENTUM VP, Exaopc and B/M9000 products, contains a stack-based buffer overflow that …EPSS 62%analysed7.8CVE-2023-26593Yokogawa b\/m9000 vp cleartext storage of sensitive data vulnerabilityCENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensitive information. If an attacker who can login or…EPSS 0.14%7.8CVE-2022-27188Yokogawa b\/m9000 vp os command injection vulnerabilityOS command injection vulnerability exists in CENTUM VP R4.01.00 to R4.03.00, CENTUM VP Small R4.01.00 to R4.03.00, CENTUM VP Basic R4.01.00 to R4.03.…EPSS 0.48%7.5CVE-2018-16196Yokogawa centum cs 3000 firmware improper input validation vulnerabilityMultiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 - R3.09.50), CENTUM CS 3000 Entry Class(R3.05.00 -…EPSS 3.3%6.5CVE-2018-8838Yokogawa b\/m9000 cs vulnerabilityA weakness in access controls in CENTUM CS 1000 all versions, CENTUM CS 3000 versions R3.09.50 and earlier, CENTUM CS 3000 Small versions R3.09.50 an…EPSS 0.29%8.8CVE-2026-7273Zyxel gs1900-8 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-base…KEVEPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2014-0782), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.