Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The application utilizes multiple methods of session management which could result in a denial of service to the remote management functions.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Link | Tags |
---|---|
https://web-material3.yokogawa.com/YSAR-18-0007-E.pdf | vendor advisory |
https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03 | third party advisory us government resource |