← Vulnerability feed

Vulnerability record · CVE-2023-26593 · published 11 April 2023

CVE-2023-26593: Yokogawa b\/m9000 vp cleartext storage of sensitive data vulnerability

Yokogawa · B\/M9000 Vp

CENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensitive information. If an attacker who can login or access the computer where the affected product is installed tampers the password file stored in the computer, the user privilege which CENTUM managed may be escalated. As a result, the control system may be operated with the escalated user privilege. To exploit this vulnerability, the following prerequisites must be met: (1)An attacker has obtained user credentials where the affected product is installed, (2)CENTUM Authentication Mode is used for user authentication when CENTUM VP is used. The affected products and versions are as follows: CENTUM CS 1000, CENTUM CS 3000 (Including CENTUM CS 3000 Entry Class) R2.01.00 to R3.09.50, CENTUM VP (Including CENTUM VP Entry Class) R4.01.00 to R4.03.00, R5.01.00 to R5.04.20, and R6.01.00 and later, B/M9000 CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R7.04.51 and R8.01.01 and later

7.8 CVSS 3.1 High EPSS 0.14% · top 97.5% CWE-312 · Cleartext storage of sensitive data
7.8CVSS 3.1 base score
0.14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
8Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

CENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensitive information. If an attacker who can login or access the computer where the affected product is installed tampers the password file stored in the computer, the user privilege which CENTUM managed may be escalated. As a result, the control system may be operated with the escalated user privilege. To exploit this vulnerability, the following prerequisites must be met: (1)An attacker has obtained user credentials where the affected product is installed, (2)CENTUM Authentication Mode is used for user authentication when CENTUM VP is used. The affected products and versions are as follows: CENTUM CS 1000, CENTUM CS 3000 (Including CENTUM CS 3000 Entry Class) R2.01.00 to R3.09.50, CENTUM VP (Including CENTUM VP Entry Class) R4.01.00 to R4.03.00, R5.01.00 to R5.04.20, and R6.01.00 and later, B/M9000 CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R7.04.51 and R8.01.01 and later

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-26593 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2014-0781Yokogawa centum cs 3000 heap-based buffer overflow vulnerabilityHeap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via cra…EPSS 25%9.1CVE-2022-26034Yokogawa b\/m9000 vp improper authentication vulnerabilityImproper authentication vulnerability in the communication protocol provided by AD (Automation Design) server of CENTUM VP R6.01.10 to R6.09.00, CENT…EPSS 0.98%9.0CVE-2014-0783Yokogawa CENTUM CS 3000 BKHOdeq.exe stack buffer overflowBKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier contains a stack-based buffer overflow that is triggered by a crafted TCP packet. Because…EPSS 68%analysed8.8CVE-2022-30707Yokogawa centum cs 3000 firmware vulnerabilityViolation of secure design principles exists in the communication of CAMS for HIS. Affected products and versions are CENTUM series where LHS4800 is …EPSS 0.58%8.3CVE-2014-3888Yokogawa CENTUM BKFSim_vhfd.exe stack buffer overflowBKFSim_vhfd.exe, a component of Yokogawa CENTUM CS 1000/CS 3000, CENTUM VP, Exaopc and B/M9000 products, contains a stack-based buffer overflow that …EPSS 62%analysed8.3CVE-2014-0782Yokogawa CENTUM and related products stack buffer overflow in BKESimmgr.exeBKESimmgr.exe in the Expanded Test Functions package of multiple Yokogawa DCS products contains a stack-based buffer overflow (CWE-121) reachable via…EPSS 57%analysed8.3CVE-2014-0784Yokogawa centum cs 3000 stack-based buffer overflow vulnerabilityStack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a c…EPSS 36%7.8CVE-2022-27188Yokogawa b\/m9000 vp os command injection vulnerabilityOS command injection vulnerability exists in CENTUM VP R4.01.00 to R4.03.00, CENTUM VP Small R4.01.00 to R4.03.00, CENTUM VP Basic R4.01.00 to R4.03.…EPSS 0.48%

Source: NIST National Vulnerability Database (record CVE-2023-26593), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.