← Vulnerability feed

Vulnerability record · CVE-2022-21808 · published 11 March 2022

CVE-2022-21808: Yokogawa centum cs 3000 firmware relative path traversal vulnerability

Yokogawa · Centum Cs 3000 Firmware

Path traversal vulnerability exists in CAMS for HIS Server contained in the following Yokogawa Electric products: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.

8.8 CVSS 3.1 High EPSS 1.1% · top 36.9% CWE-23 · Relative path traversalCWE-22 · Path traversal
8.8CVSS 3.1 base score, v2 6.0
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Path traversal vulnerability exists in CAMS for HIS Server contained in the following Yokogawa Electric products: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-21808 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-21194Yokogawa centum vp firmware hard-coded credentials vulnerabilityThe following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versi…EPSS 0.97%9.8CVE-2022-23402Yokogawa centum vp firmware hard-coded credentials vulnerabilityThe following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5.01.00 to R5.04.20 and versio…EPSS 1.00%9.8CVE-2020-5608Yokogawa centum cs 3000 firmware improper authentication vulnerabilityCAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B…EPSS 1.6%9.8CVE-2020-5609Yokogawa centum cs 3000 firmware path traversal vulnerabilityDirectory traversal vulnerability in CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP …EPSS 2.1%9.8CVE-2015-5626Yokogawa centum cs 1000 firmware out-of-bounds write vulnerabilityStack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and e…EPSS 4.2%9.8CVE-2015-5627Yokogawa centum cs 1000 firmware out-of-bounds write vulnerabilityStack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and e…EPSS 4.2%9.8CVE-2015-5628Yokogawa centum cs 1000 firmware out-of-bounds write vulnerabilityStack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and e…EPSS 6.7%8.8CVE-2022-30707Yokogawa centum cs 3000 firmware vulnerabilityViolation of secure design principles exists in the communication of CAMS for HIS. Affected products and versions are CENTUM series where LHS4800 is …EPSS 0.58%

Source: NIST National Vulnerability Database (record CVE-2022-21808), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.