Vulnerability record · CVE-2014-3888 · published 10 July 2014
CVE-2014-3888: Yokogawa CENTUM BKFSim_vhfd.exe stack buffer overflow
Yokogawa · Exaopc
BKFSim_vhfd.exe, a component of Yokogawa CENTUM CS 1000/CS 3000, CENTUM VP, Exaopc and B/M9000 products, contains a stack-based buffer overflow that is reachable when the FCS/Test Function is enabled. A crafted network packet can overwrite stack memory and lead to arbitrary code execution on the affected host. The flaw matters because these are industrial control system components, and the affected function is a test utility that may be left enabled on production systems.
Description
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier, when FCS/Test Function is enabled, allows remote attackers to execute arbitrary code via a crafted packet.
AV:N/AC:M/Au:N/C:P/I:P/A:C
Automated analysis
high priorityRemote unauthenticated code execution in ICS components with public exploit code and very high EPSS, though exploitation depends on the FCS/Test Function being enabled.
What it is
BKFSim_vhfd.exe, a component of Yokogawa CENTUM CS 1000/CS 3000, CENTUM VP, Exaopc and B/M9000 products, contains a stack-based buffer overflow that is reachable when the FCS/Test Function is enabled. A crafted network packet can overwrite stack memory and lead to arbitrary code execution on the affected host. The flaw matters because these are industrial control system components, and the affected function is a test utility that may be left enabled on production systems.
Impact
A remote, unauthenticated attacker can execute arbitrary code with the privileges of the BKFSim_vhfd.exe process, giving full control of the affected node. Because the host is part of a DCS environment, that access can be used to disrupt or manipulate process control operations.
Attack surface
The vulnerability is network-reachable (AV:N) with no authentication required (Au:N), but exploitation requires the FCS/Test Function to be enabled and a crafted packet to be delivered to the service. No user interaction is indicated by the vector.
Exploitation
CVE-2014-3888 is not listed in CISA KEV, but public exploit code exists (Packet Storm and Exploit-DB references tagged as exploits) and EPSS is very high at roughly 0.62 (99th percentile), indicating elevated likelihood of exploitation attempts.
What to do
- Apply the vendor fix per Yokogawa security advisory YSAR-14-0002E and upgrade CENTUM CS 1000, CENTUM CS 3000, CENTUM VP, Exaopc and B/M9000 to the corrected releases.
- Disable the FCS/Test Function on systems where it is not operationally required, since the flaw is only reachable when it is enabled.
- Segment and firewall the DCS network so that only trusted engineering and control hosts can reach the BKFSim_vhfd.exe service; block the port from untrusted networks.
- Monitor vendor and ICS-CERT advisories for updated guidance and apply compensating controls if patching cannot be done immediately.
Detection
- Monitor network traffic to the BKFSim_vhfd.exe service for oversized or malformed packets that could trigger the overflow.
- Alert on unexpected process crashes or restarts of BKFSim_vhfd.exe on CENTUM, Exaopc or B/M9000 hosts.
- Watch for anomalous child processes or outbound connections originating from the BKFSim_vhfd.exe process, which would indicate successful code execution.
- Audit hosts to confirm whether the FCS/Test Function is enabled and flag any that are reachable from outside the control network.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://ics-cert.us-cert.gov/advisories/ICSA-14-189-01 | Third Party AdvisoryUS Government Resource |
| http://osvdb.org/show/osvdb/108756 | |
| http://packetstormsecurity.com/files/127382/Yokogawa-CS3000-BKFSim_vhfd.exe-Buffer-Overflow.html | Exploit |
| http://www.exploit-db.com/exploits/34009 | |
| http://www.yokogawa.com/dcs/security/ysar/YSAR-14-0002E.pdf | Vendor Advisory |
| http://ics-cert.us-cert.gov/advisories/ICSA-14-189-01 | Third Party AdvisoryUS Government Resource |
| http://osvdb.org/show/osvdb/108756 | |
| http://packetstormsecurity.com/files/127382/Yokogawa-CS3000-BKFSim_vhfd.exe-Buffer-Overflow.html | Exploit |
| http://www.exploit-db.com/exploits/34009 | |
| http://www.yokogawa.com/dcs/security/ysar/YSAR-14-0002E.pdf | Vendor Advisory |
Track CVE-2014-3888 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-3888), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.