Vulnerability record · CVE-2014-0783 · published 14 March 2014
CVE-2014-0783: Yokogawa CENTUM CS 3000 BKHOdeq.exe stack buffer overflow
Yokogawa · Centum Cs 3000
BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier contains a stack-based buffer overflow that is triggered by a crafted TCP packet. Because the service is reachable over the network without authentication, a remote attacker can corrupt memory and potentially execute code on a DCS host. This is a control-system component, so successful exploitation could disrupt or manipulate an industrial process.
Description
Stack-based buffer overflow in BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.
AV:N/AC:L/Au:N/C:P/I:P/A:C
Automated analysis
high priorityRemote, unauthenticated code execution on an industrial control system with public exploit material and very high EPSS, though no confirmed in-the-wild or KEV activity.
What it is
BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier contains a stack-based buffer overflow that is triggered by a crafted TCP packet. Because the service is reachable over the network without authentication, a remote attacker can corrupt memory and potentially execute code on a DCS host. This is a control-system component, so successful exploitation could disrupt or manipulate an industrial process.
Impact
An attacker can execute arbitrary code with the privileges of the BKHOdeq.exe process, giving them a foothold on a CENTUM CS 3000 system. From there they could alter or halt process control functions.
Attack surface
The flaw is reached over the network via TCP (CVSS vector AV:N/AC:L/Au:N), so no authentication or user interaction is required. Any host that can reach the listening service can send the crafted packet.
Exploitation
No CISA KEV listing and no ransomware association are recorded, but EPSS is high at 0.684 (99.3rd percentile) and two references are tagged Exploit, indicating public exploit material exists.
What to do
- Apply the Yokogawa security update referenced in advisory ICSA-14-070-01A or upgrade past CENTUM CS 3000 R3.09.50.
- Segment the DCS network so BKHOdeq.exe is not reachable from untrusted or IT networks; restrict TCP access to required hosts only.
- Place compensating controls such as a firewall or ICS-aware IPS in front of the affected service if patching cannot be done immediately.
- Monitor Yokogawa and CISA ICS-CERT advisories for updated guidance on this and related CENTUM CS 3000 issues.
Detection
- Look for unexpected or malformed TCP traffic to the port used by BKHOdeq.exe on CENTUM CS 3000 hosts.
- Alert on crashes, restarts or abnormal termination of BKHOdeq.exe in host or application logs.
- Monitor for new or unusual processes spawned by BKHOdeq.exe, which may indicate successful code execution.
- Baseline normal communication partners for the DCS and flag connections from hosts outside that set.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-0783 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-0783), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.