CRITICAL
Yokogawa WideField3 Buffer Copy Without Checking Size of Input
Published Mar 18, 2022
9.8
CRITICALCVSS 3.1
EPSS 0.74%
Description
In Yokogawa WideField3 R1.01 - R4.03, a buffer overflow could be caused when a user loads a maliciously crafted project file.
Affected products
-
Affected
- ≥ R1.01, ≤ R4.03
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Yokogawa | WideField3 | unknown | Affected
|
- ≥ 1.01 · ≤ 4.03
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Yokogawa has prepared revision R4.04 to address this vulnerability and recommends that users switch to this revision.
For more information about this vulnerability and the associated mitigations, please see Yokogawa’s security advisory report YSAR-20-0002
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-8198 Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-20-273-02 x_refsource_CONFIRMMitigationThird Party AdvisoryUS Government Resource
- https://www.yokogawa.com/library/resources/white-papers/yokogawa-security-advisory-report-list/ x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-8198 | Advisory | |
| https://www.cisa.gov/uscert/ics/advisories/icsa-20-273-02 | x_refsource_CONFIRMMitigationThird Party AdvisoryUS Government Resource | |
| https://www.yokogawa.com/library/resources/white-papers/yokogawa-security-advisory-report-list/ | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Mar 18, 2022
Updated Apr 16, 2025
Reserved Jul 31, 2020
Link CVE-2020-16232
CISA Vulnrichment
Updated Apr 16, 2025
Red Hat
No data
GitHub
No data