Vulnerability record · CVE-2014-0782 · published 16 May 2014
CVE-2014-0782: Yokogawa CENTUM and related products stack buffer overflow in BKESimmgr.exe
Yokogawa · B\/M9000cs Software
BKESimmgr.exe in the Expanded Test Functions package of multiple Yokogawa DCS products contains a stack-based buffer overflow (CWE-121) reachable via a crafted packet. Successful exploitation allows remote code execution on control-system hosts, which matters because these are industrial control systems where a compromise can affect process availability and integrity.
Description
Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 and earlier, CENTUM VP R5.03.00 and earlier, CENTUM VP Entry Class R5.03.00 and earlier, Exaopc R3.71.02 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier allows remote attackers to execute arbitrary code via a crafted packet.
AV:N/AC:M/Au:N/C:P/I:P/A:C
Automated analysis
high priorityRemote, unauthenticated code execution in industrial control systems with a high EPSS score and public exploit discussion warrants high priority despite no KEV listing.
What it is
BKESimmgr.exe in the Expanded Test Functions package of multiple Yokogawa DCS products contains a stack-based buffer overflow (CWE-121) reachable via a crafted packet. Successful exploitation allows remote code execution on control-system hosts, which matters because these are industrial control systems where a compromise can affect process availability and integrity.
Impact
A remote attacker can execute arbitrary code with the privileges of the affected process, potentially taking control of the DCS node. The CVSS 2.0 vector indicates partial confidentiality and integrity impact with complete availability impact.
Attack surface
The flaw is network-reachable (AV:N) and requires no authentication (Au:N), though the CVSS vector notes medium access complexity (AC:M). No user interaction is indicated in the record.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS 30-day probability is 0.56839 (99th percentile), indicating high predicted likelihood, and references include a Metasploit community blog post, suggesting public exploit tooling may exist.
What to do
- Apply the vendor fix per Yokogawa advisory YSAR-14-0001E and confirm affected CENTUM, Exaopc and B/M9000 versions are upgraded.
- Isolate DCS and control-network segments from business networks and restrict access to the Expanded Test Functions service.
- Filter or block crafted packets to BKESimmgr.exe using ICS-aware firewalls or network segmentation controls.
- Monitor Yokogawa and CISA ICS advisories for updated guidance and any revised affected-version lists.
Detection
- Monitor for unexpected crashes or restarts of BKESimmgr.exe on CENTUM, Exaopc and B/M9000 hosts.
- Inspect network traffic to the Expanded Test Functions service for malformed or oversized packets.
- Alert on unusual child processes or command execution originating from BKESimmgr.exe.
- Review host logs for anomalous activity on DCS nodes around the time of service restarts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-0782 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-0782), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.