← Vulnerability feed

Vulnerability record · CVE-2018-16196 · published 9 January 2019

CVE-2018-16196: Yokogawa centum cs 3000 firmware improper input validation vulnerability

Yokogawa · Centum Cs 3000 Firmware

Multiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 - R3.09.50), CENTUM CS 3000 Entry Class(R3.05.00 - R3.09.50), CENTUM VP(R4.01.00 - R6.03.10), CENTUM VP Entry Class(R4.01.00 - R6.03.10), Exaopc(R3.10.00 - R3.75.00), PRM(R2.06.00 - R3.31.00), ProSafe-RS(R1.02.00 - R4.02.00), FAST/TOOLS(R9.02.00 - R10.02.00), B/M9000 VP(R6.03.01 - R8.01.90)) allows remote attackers to cause a denial of service attack that may result in stopping Vnet/IP Open Communication Driver's communication via unspecified vectors.

7.5 CVSS 3.0 High EPSS 3.3% · top 11.8% CWE-20 · Improper input validation
7.5CVSS 3.0 base score, v2 5.0
3.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Multiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 - R3.09.50), CENTUM CS 3000 Entry Class(R3.05.00 - R3.09.50), CENTUM VP(R4.01.00 - R6.03.10), CENTUM VP Entry Class(R4.01.00 - R6.03.10), Exaopc(R3.10.00 - R3.75.00), PRM(R2.06.00 - R3.31.00), ProSafe-RS(R1.02.00 - R4.02.00), FAST/TOOLS(R9.02.00 - R10.02.00), B/M9000 VP(R6.03.01 - R8.01.90)) allows remote attackers to cause a denial of service attack that may result in stopping Vnet/IP Open Communication Driver's communication via unspecified vectors.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-16196 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-21194Yokogawa centum vp firmware hard-coded credentials vulnerabilityThe following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versi…EPSS 0.97%9.8CVE-2022-23402Yokogawa centum vp firmware hard-coded credentials vulnerabilityThe following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5.01.00 to R5.04.20 and versio…EPSS 1.00%9.8CVE-2020-5608Yokogawa centum cs 3000 firmware improper authentication vulnerabilityCAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B…EPSS 1.6%9.8CVE-2020-5609Yokogawa centum cs 3000 firmware path traversal vulnerabilityDirectory traversal vulnerability in CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP …EPSS 2.1%9.8CVE-2015-5626Yokogawa centum cs 1000 firmware out-of-bounds write vulnerabilityStack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and e…EPSS 4.2%9.8CVE-2015-5627Yokogawa centum cs 1000 firmware out-of-bounds write vulnerabilityStack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and e…EPSS 4.2%9.8CVE-2015-5628Yokogawa centum cs 1000 firmware out-of-bounds write vulnerabilityStack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and e…EPSS 6.7%9.1CVE-2022-26034Yokogawa b\/m9000 vp improper authentication vulnerabilityImproper authentication vulnerability in the communication protocol provided by AD (Automation Design) server of CENTUM VP R6.01.10 to R6.09.00, CENT…EPSS 0.98%

Source: NIST National Vulnerability Database (record CVE-2018-16196), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.