← Vulnerability feed

Vulnerability record · CVE-2014-0783 · published 14 March 2014

CVE-2014-0783: Yokogawa CENTUM CS 3000 BKHOdeq.exe stack buffer overflow

Yokogawa · Centum Cs 3000

BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier contains a stack-based buffer overflow that is triggered by a crafted TCP packet. Because the service is reachable over the network without authentication, a remote attacker can corrupt memory and potentially execute code on a DCS host. This is a control-system component, so successful exploitation could disrupt or manipulate an industrial process.

9.0 CVSS 2.0 High EPSS 68% · top 0.7% CWE-121 · Stack-based buffer overflowCWE-119 · Memory buffer overflow
9.0CVSS 2.0 base score
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
7References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.

AV:N/AC:L/Au:N/C:P/I:P/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote, unauthenticated code execution on an industrial control system with public exploit material and very high EPSS, though no confirmed in-the-wild or KEV activity.

What it is

BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier contains a stack-based buffer overflow that is triggered by a crafted TCP packet. Because the service is reachable over the network without authentication, a remote attacker can corrupt memory and potentially execute code on a DCS host. This is a control-system component, so successful exploitation could disrupt or manipulate an industrial process.

Impact

An attacker can execute arbitrary code with the privileges of the BKHOdeq.exe process, giving them a foothold on a CENTUM CS 3000 system. From there they could alter or halt process control functions.

Attack surface

The flaw is reached over the network via TCP (CVSS vector AV:N/AC:L/Au:N), so no authentication or user interaction is required. Any host that can reach the listening service can send the crafted packet.

Exploitation

No CISA KEV listing and no ransomware association are recorded, but EPSS is high at 0.684 (99.3rd percentile) and two references are tagged Exploit, indicating public exploit material exists.

What to do

  • Apply the Yokogawa security update referenced in advisory ICSA-14-070-01A or upgrade past CENTUM CS 3000 R3.09.50.
  • Segment the DCS network so BKHOdeq.exe is not reachable from untrusted or IT networks; restrict TCP access to required hosts only.
  • Place compensating controls such as a firewall or ICS-aware IPS in front of the affected service if patching cannot be done immediately.
  • Monitor Yokogawa and CISA ICS-CERT advisories for updated guidance on this and related CENTUM CS 3000 issues.

Detection

  • Look for unexpected or malformed TCP traffic to the port used by BKHOdeq.exe on CENTUM CS 3000 hosts.
  • Alert on crashes, restarts or abnormal termination of BKHOdeq.exe in host or application logs.
  • Monitor for new or unusual processes spawned by BKHOdeq.exe, which may indicate successful code execution.
  • Baseline normal communication partners for the DCS and flag connections from hosts outside that set.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-0783 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2014-0781Yokogawa centum cs 3000 heap-based buffer overflow vulnerabilityHeap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via cra…EPSS 25%8.3CVE-2014-3888Yokogawa CENTUM BKFSim_vhfd.exe stack buffer overflowBKFSim_vhfd.exe, a component of Yokogawa CENTUM CS 1000/CS 3000, CENTUM VP, Exaopc and B/M9000 products, contains a stack-based buffer overflow that …EPSS 62%analysed8.3CVE-2014-0782Yokogawa CENTUM and related products stack buffer overflow in BKESimmgr.exeBKESimmgr.exe in the Expanded Test Functions package of multiple Yokogawa DCS products contains a stack-based buffer overflow (CWE-121) reachable via…EPSS 57%analysed8.3CVE-2014-0784Yokogawa centum cs 3000 stack-based buffer overflow vulnerabilityStack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a c…EPSS 36%7.8CVE-2023-26593Yokogawa b\/m9000 vp cleartext storage of sensitive data vulnerabilityCENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensitive information. If an attacker who can login or…EPSS 0.14%7.5CVE-2014-5208Yokogawa exaopc improper access control vulnerabilityBKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00 and R5.x through R5.04.00, a…EPSS 23%6.5CVE-2018-8838Yokogawa b\/m9000 cs vulnerabilityA weakness in access controls in CENTUM CS 1000 all versions, CENTUM CS 3000 versions R3.09.50 and earlier, CENTUM CS 3000 Small versions R3.09.50 an…EPSS 0.29%8.8CVE-2026-7273Zyxel gs1900-8 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-base…KEVEPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2014-0783), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.