CWE-428 The service path in some Yokogawa applications are unquoted and contain spaces.When the service path is unquoted and contain spaces, a local attacker could execute malicious file by the service privilege.
CVSS v3 Base Score: 8.4, Temporal Score: 8.0AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C
Yokogawa products: Exaopc(R1.01.00 - R3.77.00)• Exaplog(R1.10.00 - R3.40.00) • Exaquantum(R1.10.00 - R3.02.00)• Exaquantum/Batch(R1.01.00 - R2.50.40)• Exasmoc(All Revisions) • Exarqe(All Revisions) • GA10(R1.01.01 - R3.05.01) • InsightSuiteAE (R1.01.00 - R1.06.00)
https://bdu.fstec.ru/vul/2019-03319https://web-material3.yokogawa.com/1/28032/files/YSAR-19-0003-E.pdf