Lucene search

K
cveJpcertCVE-2014-7251
HistoryDec 06, 2014 - 3:59 p.m.

CVE-2014-7251

2014-12-0615:59:06
CWE-20
jpcert
web.nvd.nist.gov
23
cve-2014-7251
xxe vulnerability
yokogawa electric corporation
fast/tools
nvd
denial of service
cpu consumption
network traffic
arbitrary files

CVSS2

3.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:S/C:P/I:N/A:P

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

27.8%

XML external entity (XXE) vulnerability in the WebHMI server in Yokogawa Electric Corporation FAST/TOOLS before R9.05-SP2 allows local users to cause a denial of service (CPU or network traffic consumption) or read arbitrary files via unspecified vectors.

Affected configurations

Nvd
Node
yokogawafast\/toolsMatchr9.01
OR
yokogawafast\/toolsMatchr9.02
OR
yokogawafast\/toolsMatchr9.03
OR
yokogawafast\/toolsMatchr9.04
OR
yokogawafast\/toolsMatchr9.05
VendorProductVersionCPE
yokogawafast\/toolsr9.01cpe:2.3:a:yokogawa:fast\/tools:r9.01:*:*:*:*:*:*:*
yokogawafast\/toolsr9.02cpe:2.3:a:yokogawa:fast\/tools:r9.02:*:*:*:*:*:*:*
yokogawafast\/toolsr9.03cpe:2.3:a:yokogawa:fast\/tools:r9.03:*:*:*:*:*:*:*
yokogawafast\/toolsr9.04cpe:2.3:a:yokogawa:fast\/tools:r9.04:*:*:*:*:*:*:*
yokogawafast\/toolsr9.05cpe:2.3:a:yokogawa:fast\/tools:r9.05:*:*:*:*:*:*:*

CVSS2

3.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:S/C:P/I:N/A:P

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

27.8%

Related for CVE-2014-7251