← Vulnerability feed

Vulnerability record · CVE-2014-3888 · published 10 July 2014

CVE-2014-3888: Yokogawa CENTUM BKFSim_vhfd.exe stack buffer overflow

Yokogawa · Exaopc

BKFSim_vhfd.exe, a component of Yokogawa CENTUM CS 1000/CS 3000, CENTUM VP, Exaopc and B/M9000 products, contains a stack-based buffer overflow that is reachable when the FCS/Test Function is enabled. A crafted network packet can overwrite stack memory and lead to arbitrary code execution on the affected host. The flaw matters because these are industrial control system components, and the affected function is a test utility that may be left enabled on production systems.

8.3 CVSS 2.0 High EPSS 62% · top 0.8% CWE-119 · Memory buffer overflow
8.3CVSS 2.0 base score
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
15Affected product versions listed by NVD
10References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier, when FCS/Test Function is enabled, allows remote attackers to execute arbitrary code via a crafted packet.

AV:N/AC:M/Au:N/C:P/I:P/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote unauthenticated code execution in ICS components with public exploit code and very high EPSS, though exploitation depends on the FCS/Test Function being enabled.

What it is

BKFSim_vhfd.exe, a component of Yokogawa CENTUM CS 1000/CS 3000, CENTUM VP, Exaopc and B/M9000 products, contains a stack-based buffer overflow that is reachable when the FCS/Test Function is enabled. A crafted network packet can overwrite stack memory and lead to arbitrary code execution on the affected host. The flaw matters because these are industrial control system components, and the affected function is a test utility that may be left enabled on production systems.

Impact

A remote, unauthenticated attacker can execute arbitrary code with the privileges of the BKFSim_vhfd.exe process, giving full control of the affected node. Because the host is part of a DCS environment, that access can be used to disrupt or manipulate process control operations.

Attack surface

The vulnerability is network-reachable (AV:N) with no authentication required (Au:N), but exploitation requires the FCS/Test Function to be enabled and a crafted packet to be delivered to the service. No user interaction is indicated by the vector.

Exploitation

CVE-2014-3888 is not listed in CISA KEV, but public exploit code exists (Packet Storm and Exploit-DB references tagged as exploits) and EPSS is very high at roughly 0.62 (99th percentile), indicating elevated likelihood of exploitation attempts.

What to do

  • Apply the vendor fix per Yokogawa security advisory YSAR-14-0002E and upgrade CENTUM CS 1000, CENTUM CS 3000, CENTUM VP, Exaopc and B/M9000 to the corrected releases.
  • Disable the FCS/Test Function on systems where it is not operationally required, since the flaw is only reachable when it is enabled.
  • Segment and firewall the DCS network so that only trusted engineering and control hosts can reach the BKFSim_vhfd.exe service; block the port from untrusted networks.
  • Monitor vendor and ICS-CERT advisories for updated guidance and apply compensating controls if patching cannot be done immediately.

Detection

  • Monitor network traffic to the BKFSim_vhfd.exe service for oversized or malformed packets that could trigger the overflow.
  • Alert on unexpected process crashes or restarts of BKFSim_vhfd.exe on CENTUM, Exaopc or B/M9000 hosts.
  • Watch for anomalous child processes or outbound connections originating from the BKFSim_vhfd.exe process, which would indicate successful code execution.
  • Audit hosts to confirm whether the FCS/Test Function is enabled and flag any that are reachable from outside the control network.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-3888 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2022-26034Yokogawa b\/m9000 vp improper authentication vulnerabilityImproper authentication vulnerability in the communication protocol provided by AD (Automation Design) server of CENTUM VP R6.01.10 to R6.09.00, CENT…EPSS 0.98%8.8CVE-2022-30707Yokogawa centum cs 3000 firmware vulnerabilityViolation of secure design principles exists in the communication of CAMS for HIS. Affected products and versions are CENTUM series where LHS4800 is …EPSS 0.58%8.3CVE-2014-0782Yokogawa CENTUM and related products stack buffer overflow in BKESimmgr.exeBKESimmgr.exe in the Expanded Test Functions package of multiple Yokogawa DCS products contains a stack-based buffer overflow (CWE-121) reachable via…EPSS 57%analysed7.8CVE-2023-26593Yokogawa b\/m9000 vp cleartext storage of sensitive data vulnerabilityCENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensitive information. If an attacker who can login or…EPSS 0.14%7.8CVE-2022-27188Yokogawa b\/m9000 vp os command injection vulnerabilityOS command injection vulnerability exists in CENTUM VP R4.01.00 to R4.03.00, CENTUM VP Small R4.01.00 to R4.03.00, CENTUM VP Basic R4.01.00 to R4.03.…EPSS 0.48%7.5CVE-2018-16196Yokogawa centum cs 3000 firmware improper input validation vulnerabilityMultiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 - R3.09.50), CENTUM CS 3000 Entry Class(R3.05.00 -…EPSS 3.3%6.5CVE-2018-8838Yokogawa b\/m9000 cs vulnerabilityA weakness in access controls in CENTUM CS 1000 all versions, CENTUM CS 3000 versions R3.09.50 and earlier, CENTUM CS 3000 Small versions R3.09.50 an…EPSS 0.29%8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed

Source: NIST National Vulnerability Database (record CVE-2014-3888), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.