CVE-2014-3888

high
Published 2014-07-10 ยท Modified 2026-05-06
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
9.3

Description

Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier, when FCS/Test Function is enabled, allows remote attackers to execute arbitrary code via a crafted packet.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-34009 remote windows
Metasploit ยท 2014-07-08

Yokogawa CS3000 - 'BKFSim_vhfd.exe' Remote Buffer Overflow (Metasploit)

Source code queued for fetch โ€” refresh in a moment.

Metasploit modules

Yokogawa CS3000 BKFSim_vhfd.exe Buffer Overflow
Source fetch failed: fetch_error โ€” view the original via the link above.

Application impact

VendorProductVersionsFixed
yokogawaexaopc{"endIncluding":"3.72.00"}
yokogawaexaopc3.71.02
yokogawab\/m9000cs_software{"endIncluding":"5.05.01"}
yokogawacentum_vp_entry_class_software{"endIncluding":"5.03.00"}
yokogawacentum_vp_software{"endIncluding":"5.03.20"}
yokogawacentum_vp_software4.03.00
yokogawab\/m9000_vp_software{"endIncluding":"7.03.01"}
yokogawacentum_cs_3000r3.01
yokogawacentum_cs_3000r3.02
yokogawacentum_cs_3000r3.03
yokogawacentum_cs_3000r3.04
yokogawacentum_cs_3000r3.05
yokogawacentum_cs_3000r3.06
yokogawacentum_cs_3000r3.07
yokogawacentum_cs_3000r3.08
yokogawacentum_cs_3000r3.08.50
yokogawacentum_cs_3000r3.08.70
yokogawacentum_cs_3000r3.09
yokogawacentum_cs_3000r3.09.50
yokogawacentum_cs_3000_software{"endIncluding":"2.23.00"}
yokogawacentum_cs_1000_software-
yokogawacentum_cs_3000_entry_class_software{"endIncluding":"3.09.50"}

References

CWEs

CWE-119

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.