{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T14:03:41.242","vulnerabilities":[{"cve":{"id":"CVE-2022-30997","sourceIdentifier":"vultures@jpcert.or.jp","published":"2022-06-28T13:15:12.607","lastModified":"2026-06-17T04:44:34.403","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Use of hard-coded credentials vulnerability exists in STARDOM FCN Controller and FCJ Controller R4.10 to R4.31, which may allow an attacker with an administrative privilege to read/change configuration settings or update the controller with tampered firmware."},{"lang":"es","value":"Se presenta una vulnerabilidad en el uso de credenciales embebidas en el controlador STARDOM FCN y en el controlador FCJ versiones R4.10 a R4.31, que puede permitir a un atacante con un privilegio administrativo leer/cambiar los ajustes de configuración o actualizar el controlador con un firmware manipulado"}],"affected":[{"source":"vultures@jpcert.or.jp","affectedData":[{"vendor":"Yokogawa Electric Corporation","product":"STARDOM Controller","versions":[{"version":"STARDOM FCN Controller and FCJ Controller R4.10 to R4.31","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"yokogawa","product":"stardom_fcj_firmware","defaultStatus":"unknown","cpes":["cpe:2.3:o:yokogawa:stardom_fcj_firmware:r4.10:*:*:*:*:*:*:*"],"versions":[{"version":"r4.10","lessThanOrEqual":"r4.31","versionType":"custom","status":"affected"}]},{"vendor":"yokogawa","product":"stardom_fcn_firmware","defaultStatus":"unknown","cpes":["cpe:2.3:o:yokogawa:stardom_fcn_firmware:r4.10:*:*:*:*:*:*:*"],"versions":[{"version":"r4.10","lessThanOrEqual":"r4.31","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.4,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.0,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-26T19:56:59.327177Z","id":"CVE-2022-30997","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-798"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-798"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:yokogawa:stardom_fcj_firmware:*:*:*:*:*:*:*:*","versionStartIncluding":"r4.10","versionEndIncluding":"r4.31","matchCriteriaId":"CD9C1D4C-918E-4513-A8B9-FEFD2B5BF4DA"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:yokogawa:stardom_fcj:-:*:*:*:*:*:*:*","matchCriteriaId":"37EFAADB-EF41-4B63-A9C4-9A410682F47D"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:yokogawa:stardom_fcn_firmware:*:*:*:*:*:*:*:*","versionStartIncluding":"r4.10","versionEndIncluding":"r4.31","matchCriteriaId":"E2CA2151-1567-4F30-BF53-6A537EA3E505"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:yokogawa:stardom_fcn:-:*:*:*:*:*:*:*","matchCriteriaId":"6051604E-7FAF-44D7-BDB6-7D2D71DFC416"}]}]}],"references":[{"url":"https://jvn.jp/vu/JVNVU95452299/index.html","source":"vultures@jpcert.or.jp","tags":["Mitigation","Third Party Advisory","VDB Entry"]},{"url":"https://web-material3.yokogawa.com/1/32885/files/YSAR-22-0007-E.pdf","source":"vultures@jpcert.or.jp","tags":["Mitigation","Vendor Advisory"]},{"url":"https://web-material3.yokogawa.com/19/32885/files/YSAR-22-0007-J.pdf","source":"vultures@jpcert.or.jp","tags":["Mitigation","Vendor Advisory"]},{"url":"https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-01","source":"vultures@jpcert.or.jp","tags":["Mitigation","Third Party Advisory","US Government Resource"]},{"url":"https://jvn.jp/vu/JVNVU95452299/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Third Party Advisory","VDB Entry"]},{"url":"https://web-material3.yokogawa.com/1/32885/files/YSAR-22-0007-E.pdf","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Vendor Advisory"]},{"url":"https://web-material3.yokogawa.com/19/32885/files/YSAR-22-0007-J.pdf","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Vendor Advisory"]},{"url":"https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-01","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Third Party Advisory","US Government Resource"]}]}}]}