Positive Technologies helps eliminate

Positive Technologies helps eliminate vulnerabilities in Yokogawa’s CENTUM DCS (distributed control system) used in over 10,000 businesses

Natalia Tlyapova and Ivan Kurnakov, specialists from Positive Technologies’ ICS Security Division, have identified vulnerabilities in a component of the distributed control system (DCS) by the Japanese firm Yokogawa. This DCS is used by over 10 thousand enterprises in the oil and gas, chemical, and energy sectors, as well as by water services and firms across other industries.

The vulnerabilities were found in the Consolidated Alarm Management Software (CAMS) for HIS (Human Interface Station). This component is responsible for managing events and emergency messages in the industrial control system.

The first vulnerability (CVE-2020-5608, with the score of 8.1 on the CVSS v3.0 scale) involved a lack of authentication when communicating over a specialized protocol, making it possible for unauthenticated users to interact with the server.

The second vulnerability (CVE-2020-5609, with the score of 8.1 on the CVSS v3.0 scale) made path traversal possible, opening up the opportunity to arbitrarily overwrite text files. These included regular files that happened to be saved on the same disk as the system, as well as files essential to the operation of the DCS (for example, configuration files). This violated the integrity of information stored on attacked hosts, and made the execution of arbitrary code possible.

CENTUM DCS is widely used by firms and enterprises around the world. Vulnerabilities in industrial control systems (ICSs) are always dangerous and have the potential to extensively impact the operations of attacked firms. The ability to execute arbitrary code on the server of an industrial segment gives attackers vast opportunities for developing their attacks further,” explains Vladimir Nazarov, Head of ICS Security at Positive Technologies.

The vulnerabilities can be eliminated by installing the recommended updates released by the manufacturer. Cybersecurity incidents and ICS vulnerabilities can also be detected using Positive Technologies’ proprietary software products, PT Industrial Security Incident Manager (PT ISIM) and MaxPatrol 8.

 

Share this article on Twitter or LinkedIn.

See more news here.

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne picture 2025

Rebecca Spayne

Managing
EDITOR

Georgina Turner image

Georgina Turner

Sales
Manager

Afua Akoto image - Security Buyer

Afua Akoto

Marketing Manager

Read the Latest Issue

Follow us on X

Follow us on X

Click Here

Follow us on LinkedIn

Follow us on LinkedIn

Click Here

Advertise here

Reach decision makers and amplify your marketing

Advertise here

Click Here

Related News

Christina Alexander Judge - SecurityBuyer

Christina Alexander Announced as Security Buyer Awards Judge

Security Buyer is proud to announce Christina Alexander as the latest addition to the distinguished judging panel for the Security…
Milestone - SecurityBuyer

Milestone Systems updates across XProtect, BriefCam, Arcules

Milestone Systems today announced updates across its complete security technology portfolio with releases for XProtect
ASSA ABLOY SMARTair - Security Buyer

More flexible management of Gen-Z student accommodation

Almost everyone attending university for the first time is now a digital native. They expect the convenience…
ICT - securitybuyer

ICT announces Martin Vermaak as COO

Integrated Control Technology (ICT), a leading provider of intelligent access control, intrusion detection, building automation..
FLIR - security buyer

New FLIR camera for Perimeter Security

FLIR, a Teledyne Technologies company, today released its newest high-resolution visible/thermal security camera for commercial..
Contacta - Security Buyer

Contacta launches Level 8 ballistically-resistant window intercom

Assistive listening specialist, Contacta, has launched the world’s first window intercom system with a Level 8 UL752 approval.
Big Interview Abdullah Tanoli

Big Interview – Hero of Leicester Square

Rebecca Spayne of Security Buyer has the privilege of speaking with a real-life hero, Abdullah Tanoli, the hero of Leicester Square..
SentinelOne & AWS - Security Buyer

SentinelOne Teams with AWS to bring Cloud Security Protection

SentinelOne announced that it is a launch partner for the new AWS Security Hub. The new collaboration builds on a long standing..
Genetec - Security Buyer

Genetec and Hanwha Vision

The latest in our ongoing series introducing Hanwha Vision’s pioneering partners, leads us to Ben Durrant, Account Executive at Genetec Inc.
Altronix - SecurityBuyer

Altronix POE367 Delivers 277VAC Support

Altronix has expanded its power product line with the new POE367 power supply/charger designed specifically for 277VAC input environments.
Scroll to Top