ID

VAR-E-201411-0147


CVE

cve_id:CVE-2014-7251

Trust: 0.3

sources: BID: 71379

TITLE

Yokogawa FAST/TOOLS CVE-2014-7251 XML External Entity Injection Vulnerability

Trust: 0.3

sources: BID: 71379

DESCRIPTION

Yokogawa FAST/TOOLS is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to obtain potentially sensitive information or cause a denial-of-service condition. This may lead to further attacks.
Yokogawa FAST/TOOLS R9.01 through R9.05 are vulnerable.

Trust: 0.3

sources: BID: 71379

AFFECTED PRODUCTS

vendor:yokogawamodel:fast/tools r9.05scope: - version: -

Trust: 0.3

vendor:yokogawamodel:fast/tools r9.01scope: - version: -

Trust: 0.3

vendor:yokogawamodel:fast/tools r9.05-sp2scope:neversion: -

Trust: 0.3

sources: BID: 71379

EXPLOIT

An attacker can exploit this issue using readily available tools..

Trust: 0.3

sources: BID: 71379

PRICE

Free

Trust: 0.3

sources: BID: 71379

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 71379

CREDITS

Timur Yunusov, Alexey Osipov and Ilya Karpov of Positive Technologies.

Trust: 0.3

sources: BID: 71379

EXTERNAL IDS

db:JVNid:JVN54775800

Trust: 0.3

db:NVDid:CVE-2014-7251

Trust: 0.3

db:BIDid:71379

Trust: 0.3

sources: BID: 71379

REFERENCES

url:http://jvn.jp/en/jp/jvn54775800/index.html

Trust: 0.3

url:http://www.yokogawa.com/

Trust: 0.3

sources: BID: 71379

SOURCES

db:BIDid:71379

LAST UPDATE DATE

2022-07-27T09:56:33.673000+00:00


SOURCES UPDATE DATE

db:BIDid:71379date:2014-11-28T00:00:00

SOURCES RELEASE DATE

db:BIDid:71379date:2014-11-28T00:00:00