<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=yokogawa+fasttools%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 01:33:31 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 01:33:31 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=yokogawa+fasttools%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=yokogawa+fasttools%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Yokogawa FAST/TOOLS and CI Server]]></title>
<description><![CDATA[View CSAF
Summary
Successful exploitation of this vulnerability may return a response containing the CI Server setting information.
The following versions of Yokogawa FAST/TOOLS and CI Server are affected:

FAST/TOOLS >=R9.01|=R1.01|=R9.01|=R1.01|]]></description>
<link>https://tsecurity.de/de/3625456/it-security-nachrichten/yokogawa-fasttools-and-ci-server/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625456/it-security-nachrichten/yokogawa-fasttools-and-ci-server/</guid>
<pubDate>Thu, 25 Jun 2026 19:24:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-176-01.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability may return a response containing the CI Server setting information.</strong></p>
<p>The following versions of Yokogawa FAST/TOOLS and CI Server are affected:</p>
<ul>
<li>FAST/TOOLS &gt;=R9.01|&lt;=R10.04 </li>
<li>Collaborative Information Server (CI Server) &gt;=R1.01|&lt;=R1.04</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 7.5</td>
<td>Yokogawa</td>
<td>Yokogawa FAST/TOOLS and CI Server</td>
<td>Cleartext Transmission of Sensitive Information</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy, Food and Agriculture</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Japan</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-11833</a></h3>
<div class="csaf-accordion-content">
<p>The web server may return a response containing the CI Server setting information. This information could be exploited by an attacker for other attacks.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-11833">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa FAST/TOOLS and CI Server</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa FAST/TOOLS: &gt;=R9.01|&lt;=R10.04, Yokogawa Collaborative Information Server (CI Server): &gt;=R1.01|&lt;=R1.04</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Yokogawa recommends users update FAST/TOOLS up to R10.04 and apply patch software (R10.04 SP4).</p>
<p><strong>Mitigation</strong><br>Yokogawa recommends users update Collaborative Information Server (CI Server) up to R1.05.</p>
<p><strong>Mitigation</strong><br>For more information and details on implementing these mitigations, users should see the Yokogawa security advisory report YSAR-26-0004 at: <a href="https://web-material3.yokogawa.com/1/39777/files/YSAR-26-0004-E.pdf">https://web-material3.yokogawa.com/1/39777/files/YSAR-26-0004-E.pdf</a></p>
<p><strong>Mitigation</strong><br>For questions related to this report, please contact the below. <br><a href="https://contact.yokogawa.com/cs/gw?c-id=000498">https://contact.yokogawa.com/cs/gw?c-id=000498</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/319.html">CWE-319 Cleartext Transmission of Sensitive Information</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
<tr>
<td>4.0</td>
<td>8.2</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Yokogawa reported this vulnerability to JPCERT/CC</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>
<p>When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-06-25</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-06-25</td>
<td>1</td>
<td>Initial CISA Republication of Yokogawa Security Advisory Report YSAR-26-0004</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-11833 | Yokogawa Electric FAST/TOOLS/CI Server up to R10.04 cleartext transmission (EUVD-2026-38411)]]></title>
<description><![CDATA[A vulnerability has been found in Yokogawa Electric FAST, TOOLS and CI Server up to R10.04 and classified as problematic. This vulnerability affects unknown code. Performing a manipulation results in cleartext transmission of sensitive information.

This vulnerability is reported as CVE-2026-1183...]]></description>
<link>https://tsecurity.de/de/3618509/sicherheitsluecken/cve-2026-11833-yokogawa-electric-fasttoolsci-server-up-to-r1004-cleartext-transmission-euvd-2026-38411/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618509/sicherheitsluecken/cve-2026-11833-yokogawa-electric-fasttoolsci-server-up-to-r1004-cleartext-transmission-euvd-2026-38411/</guid>
<pubDate>Tue, 23 Jun 2026 15:54:17 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/yokogawa_electric:fast">Yokogawa Electric FAST, TOOLS and CI Server up to R10.04</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This vulnerability affects unknown code. Performing a manipulation results in cleartext transmission of sensitive information.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-11833">CVE-2026-11833</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Week in Vulnerabilities: Azure AI, Spring AI, Fortinet, and Critical ICS Exposure]]></title>
<description><![CDATA[Cyble Research & Intelligence Labs (CRIL) in its weekly vulnerability report tracked 1,431 bugs last week.


Of these, over 270 vulnerabilities have publicly available Proof-of-Concept (PoC) exploits, significantly accelerating exploitation timelines and increasing real-world attack likelihood.

...]]></description>
<link>https://tsecurity.de/de/3438416/it-security-nachrichten/the-week-in-vulnerabilities-azure-ai-spring-ai-fortinet-and-critical-ics-exposure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3438416/it-security-nachrichten/the-week-in-vulnerabilities-azure-ai-spring-ai-fortinet-and-critical-ics-exposure/</guid>
<pubDate>Thu, 16 Apr 2026 13:07:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="800" height="400" src="https://cyble.com/wp-content/uploads/2026/04/Weekly-Vulnerability-Report_Apr16.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Weekly Vulnerability Report, Cyble Weekly Vulnerability Report, Vulnerability Intelligence, Vulnerability Management" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/04/Weekly-Vulnerability-Report_Apr16.webp 800w, https://cyble.com/wp-content/uploads/2026/04/Weekly-Vulnerability-Report_Apr16-300x150.webp 300w, https://cyble.com/wp-content/uploads/2026/04/Weekly-Vulnerability-Report_Apr16-768x384.webp 768w" sizes="(max-width: 800px) 100vw, 800px" title="The Week in Vulnerabilities: Azure AI, Spring AI, Fortinet, and Critical ICS Exposure 1"></p>
<p><!-- wp:paragraph --></p>
<p>Cyble Research &amp; Intelligence Labs (CRIL) in its weekly vulnerability report tracked 1,431 bugs last week.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Of these, over 270 <a href="https://cyble.com/knowledge-hub/10-vulnerability-types-threat-actors/">vulnerabilities</a> have publicly available Proof-of-Concept (PoC) exploits, significantly accelerating exploitation timelines and increasing real-world attack likelihood.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Additionally, 3 vulnerabilities were actively discussed across underground forums, signaling strong adversarial interest and rapid weaponization.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A total of 130 vulnerabilities were rated critical under CVSS v3.1, while 45 were rated critical under CVSS v4.0, reflecting the severity of disclosed issues.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Furthermore, CISA added 3 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>On the industrial front, CISA issued 5 ICS advisories covering 6 vulnerabilities, impacting vendors such as Siemens, Hitachi Energy, and Yokogawa.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Weekly Vulnerability Report’s Top 5 Vulnerabilities</strong></h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-32213 — Microsoft Azure AI Foundry (Critical)</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-32213 is a critical authorization bypass vulnerability in Microsoft Azure AI Foundry.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The flaw exists in the platform’s authorization logic, allowing unauthenticated attackers to bypass security checks and grant themselves administrative privileges. Successful exploitation enables full control over AI environments and associated resources.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-35022 — Claude Code CLI / Agent SDK (Critical)</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-35022 is a critical OS command injection vulnerability affecting Anthropic’s Claude Code CLI and Agent SDK.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The vulnerability allows attackers to inject malicious commands into development workflows, resulting in <a href="https://cyble.com/blog/springshell-remote-code-execution-vulnerability/">remote code</a> execution and potential compromise of AI pipelines.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-22738 — Spring AI (Critical)</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22738">CVE-2026-22738</a> is a remote code execution vulnerability in Spring AI caused by improper input sanitization in expression evaluation.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Attackers can inject <a href="https://cyble.com/knowledge-hub/what-is-malware/">malicious</a> expressions that are executed by the Spring Expression Language, leading to complete application and server compromise.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-4631 — Cockpit (Critical)</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-4631 is an unauthenticated remote code execution vulnerability in Cockpit, a web-based Linux server management interface.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The flaw allows attackers to execute arbitrary commands without authentication, potentially leading to full system takeover in enterprise environments.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-35616 — Fortinet FortiClient EMS (Critical)</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-35616 is a critical authentication bypass vulnerability in Fortinet FortiClient EMS.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Attackers can bypass authentication and execute arbitrary commands, leading to complete compromise of <a href="https://cyble.com/solutions/endpoint-security-solution/">endpoint management</a> systems.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":116726,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/04/image-32.png" alt="Weekly Vulnerability Report, Cyble Weekly Vulnerability Report, Vulnerability Intelligence, Vulnerability Management" class="wp-image-116726"><figcaption class="wp-element-caption"><em>Data Source: Cyble Vision</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Vulnerabilities Added to CISA KEV</strong></h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>CISA continues to expand its KEV catalog, reflecting real-world exploitation trends.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><em>Notable addition:</em></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-35616 — Fortinet FortiClient EMS</strong><br>This vulnerability enables authentication bypass and remote command execution, making it a high-priority remediation target.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The inclusion of enterprise security tools in KEV highlights attackers’ focus on compromising centralized management systems.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Critical ICS Vulnerabilities</strong></h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>CISA issued 5 ICS advisories covering 6 vulnerabilities, many of which impact critical infrastructure environments.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":116725,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/04/image-31.png" alt="Weekly Vulnerability Report, Cyble Weekly Vulnerability Report, Vulnerability Intelligence, Vulnerability Management" class="wp-image-116725"><figcaption class="wp-element-caption"><em>Data Source: Cyble Vision</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-1579 — PX4 Autopilot (Critical)</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A missing authentication vulnerability allowing attackers to execute critical functions without credentials.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This flaw poses risks to autonomous and unmanned systems, potentially enabling unauthorized control.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-3356 — Anritsu Systems (Critical)</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This vulnerability involves missing authentication in Anritsu devices, allowing attackers to gain unauthorized access.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2025-10492 — Hitachi Energy Ellipse (Critical)</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A deserialization vulnerability enabling attackers to execute arbitrary code within industrial systems.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Siemens SICAM 8 (Chained Risk)</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Two vulnerabilities affecting Siemens SICAM 8 systems—resource exhaustion and out-of-bounds write—can be chained together.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This creates a denial-of-service risk capable of disrupting industrial processes and operational visibility.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2025-7741 — Yokogawa CENTUM VP (Medium)</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A hard-coded password vulnerability that weakens authentication mechanisms and increases risk of unauthorized access.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Critical Infrastructure Sectors Spotlight</strong></h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:image {"id":116727,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/04/image-33.png" alt="Weekly Vulnerability Report, Cyble Weekly Vulnerability Report, Vulnerability Intelligence, Vulnerability Management" class="wp-image-116727"><figcaption class="wp-element-caption"><em>Data Source: Cyble Vision</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><em>Analysis indicates:</em></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Critical Manufacturing appears in 66.7% of vulnerabilities</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Cross-sector exposure spans:<!-- wp:list -->
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Transportation Systems</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Emergency Services</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Defense Industrial Base</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Communications</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p></li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>This highlights interconnected infrastructure risks, where a single vulnerability can cascade across multiple sectors.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Conclusion</strong></h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>This week’s findings highlight several critical trends:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Expansion of vulnerabilities into AI and development ecosystems</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Increasing exploitation of enterprise management platforms</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Continued weaknesses in industrial control systems</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Cross-sector risk amplification in critical infrastructure</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>With 270+ PoCs, KEV-confirmed exploitation, and emerging threats in AI frameworks, organizations face heightened risk across both digital and physical environments.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Key Recommendations</strong></h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Prioritize vulnerabilities with PoCs and KEV inclusion</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Secure AI development environments and pipelines</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Patch enterprise management and remote access systems immediately</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Implement strict authentication and access control mechanisms</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Segment IT and OT networks to prevent lateral movement</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Apply compensating controls for unpatched ICS vulnerabilities</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Monitor underground forums and <a class="wpil_keyword_link" href="https://cyble.com/solutions/cyber-threat-intelligence/" target="_blank" rel="noopener" title="Best Threat Intelligence Solution | Strengthen Security" data-wpil-keyword-link="linked" data-wpil-monitor-id="30843">threat intelligence</a> feeds</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Conduct continuous vulnerability assessments and penetration testing</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:separator --></p>
<hr class="wp-block-separator has-alpha-channel-opacity">
<!-- /wp:separator -->
<p><!-- wp:paragraph --></p>
<p><em>Cyble’s </em><a href="https://cyble.com/solutions/attack-surface-management/"><em>attack surface management</em></a><em> and </em><a href="https://cyble.com/solutions/vulnerability-management/"><em>vulnerability intelligence solutions</em></a><em> help organizations proactively identify risks, prioritize remediation, and detect emerging threats. By integrating intelligence-driven security strategies, organizations can strengthen resilience across enterprise and critical infrastructure environments.</em></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/blog/cyble-weekly-vulnerability-report-apr-16/">The Week in Vulnerabilities: Azure AI, Spring AI, Fortinet, and Critical ICS Exposure</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa CENTUM VP]]></title>
<description><![CDATA[View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to login as the PROG user and modify permissions. The following versions of Yokogawa CENTUM VP are affected: CENTUM VP >=R5.01.00| CENTUM VP >=R6.01.00| CENTUM VP vR7.01.00 (CVE-2025-7741)…
Read more →
The pos...]]></description>
<link>https://tsecurity.de/de/3403512/it-security-nachrichten/yokogawa-centum-vp/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3403512/it-security-nachrichten/yokogawa-centum-vp/</guid>
<pubDate>Thu, 02 Apr 2026 19:05:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to login as the PROG user and modify permissions. The following versions of Yokogawa CENTUM VP are affected: CENTUM VP &gt;=R5.01.00| CENTUM VP &gt;=R6.01.00| CENTUM VP vR7.01.00 (CVE-2025-7741)…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/yokogawa-centum-vp/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/yokogawa-centum-vp/">Yokogawa CENTUM VP</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa CENTUM VP]]></title>
<description><![CDATA[View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to login as the PROG user and modify permissions.
The following versions of Yokogawa CENTUM VP are affected:

CENTUM VP >=R5.01.00|
CENTUM VP >=R6.01.00|
CENTUM VP vR7.01.00 (CVE-2025-7741)





CVSS
Vendor
Eq...]]></description>
<link>https://tsecurity.de/de/3403477/it-security-nachrichten/yokogawa-centum-vp/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3403477/it-security-nachrichten/yokogawa-centum-vp/</guid>
<pubDate>Thu, 02 Apr 2026 18:52:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-092-02.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability could allow an attacker to login as the PROG user and modify permissions.</strong></p>
<p>The following versions of Yokogawa CENTUM VP are affected:</p>
<ul>
<li>CENTUM VP &gt;=R5.01.00|</li>
<li>CENTUM VP &gt;=R6.01.00|</li>
<li>CENTUM VP vR7.01.00 (CVE-2025-7741)</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 4</td>
<td>Yokogawa</td>
<td>Yokogawa CENTUM VP</td>
<td>Use of Hard-coded Password</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy, Food and Agriculture</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Japan</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-7741</a></h3>
<div class="csaf-accordion-content">
<p>Affected products contain a hardcoded password for the user account (PROG) used for CENTUM Authentication Mode within the system. Under the following conditions, there is a risk that an attacker could log in as the PROG user. The default permission for the PROG users is S1 permission (equivalent to OFFUSER). Therefore, for properly permission-controlled targets of operation and monitoring, even if an attacker logs in as the PROG user, the risk of critical operations or configuration changes being performed is considered low. If the PROG user's permissions have been changed for any reason, there is a risk that operations or configuration changes may be performed under the modified permissions. Additionally, exploiting this vulnerability requires an attacker to already have access to the HIS screen controls.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-7741">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa CENTUM VP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa CENTUM VP: &gt;=R5.01.00|&lt;R5.04.20, Yokogawa CENTUM VP: &gt;=R6.01.00|&lt;R6.12.00, Yokogawa CENTUM VP: vR7.01.00</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users applying the following mitigations to affected versions:</p>
<p><strong>Vendor fix</strong><br>CENTUM VP R5.01.00 to R5.04.20: Change the user authentication mode to Windows Authentication Mode.</p>
<p><strong>Vendor fix</strong><br>CENTUM VP R6.01.00 to R6.12.00: Change the user authentication mode to Windows Authentication Mode.</p>
<p><strong>Vendor fix</strong><br>CENTUM VP R7.01.00: Apply patch software R7.01.10.</p>
<p><strong>Mitigation</strong><br>NOTE:Changing to Windows Authentication Mode requires engineering work. If users wish to make this change, please contact Yokogawa directly https://contact.yokogawa.com/cs/gw?c-id=000498.<br><a href="https://contact.yokogawa.com/cs/gw?c-id=000498">https://contact.yokogawa.com/cs/gw?c-id=000498</a></p>
<p><strong>Mitigation</strong><br>For more information and details on implementing these mitigations, users should see the Yokogawa advisory YSAR-26-0003 at https://web-material3.yokogawa.com/1/39281/files/YSAR-26-0003-E.pdf<br><a href="https://web-material3.yokogawa.com/1/39281/files/YSAR-26-0003-E.pdf">https://web-material3.yokogawa.com/1/39281/files/YSAR-26-0003-E.pdf</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/259.html">CWE-259 Use of Hard-coded Password</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Yokogawa reported this vulnerability to CISA</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>
<p>Do not click web links or open attachments in unsolicited email messages.</p>
<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>
<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>
<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely. This vulnerability has a high attack complexity.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-04-02</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-04-02</td>
<td>1</td>
<td>Initial Republication of YSAR-26-0003</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-7741 | Yokogawa Electric CENTUM VP up to R5.04.20/R6.12.00/R7.01.00 hard-coded password (EUVD-2025-209116)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Yokogawa Electric CENTUM VP up to R5.04.20/R6.12.00/R7.01.00. This impacts an unknown function. The manipulation results in use of hard-coded password.

This vulnerability is reported as CVE-2025-7741. The attack requires a local ...]]></description>
<link>https://tsecurity.de/de/3392123/sicherheitsluecken/cve-2025-7741-yokogawa-electric-centum-vp-up-to-r50420r61200r70100-hard-coded-password-euvd-2025-209116/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3392123/sicherheitsluecken/cve-2025-7741-yokogawa-electric-centum-vp-up-to-r50420r61200r70100-hard-coded-password-euvd-2025-209116/</guid>
<pubDate>Mon, 30 Mar 2026 09:22:31 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/yokogawa_electric:centum_vp">Yokogawa Electric CENTUM VP up to R5.04.20/R6.12.00/R7.01.00</a>. This impacts an unknown function. The manipulation results in use of hard-coded password.

This vulnerability is reported as <a href="https://vuldb.com/source_cve/354133">CVE-2025-7741</a>. The attack requires a local approach. No exploit exists.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Week in Vulnerabilities: SolarWinds, Ivanti, and Critical ICS Exposure]]></title>
<description><![CDATA[Cyble Research & Intelligence Labs (CRIL) tracked 1,158 vulnerabilities last week. Of these, 251 vulnerabilities already have publicly available Proof-of-Concept (PoC) exploits, significantly increasing the likelihood of real-world attacks. 


A total of 94 vulnerabilities were rated critical und...]]></description>
<link>https://tsecurity.de/de/3347471/it-security-nachrichten/the-week-in-vulnerabilities-solarwinds-ivanti-and-critical-ics-exposure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3347471/it-security-nachrichten/the-week-in-vulnerabilities-solarwinds-ivanti-and-critical-ics-exposure/</guid>
<pubDate>Fri, 13 Mar 2026 15:22:14 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="800" height="400" src="https://cyble.com/wp-content/uploads/2026/02/Cyble-vulnerability-Report-1.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Cyble vulnerability Report" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/02/Cyble-vulnerability-Report-1.webp 800w, https://cyble.com/wp-content/uploads/2026/02/Cyble-vulnerability-Report-1-300x150.webp 300w, https://cyble.com/wp-content/uploads/2026/02/Cyble-vulnerability-Report-1-768x384.webp 768w, https://cyble.com/wp-content/uploads/2026/02/Cyble-vulnerability-Report-1-600x300.webp 600w" sizes="(max-width: 800px) 100vw, 800px" title="The Week in Vulnerabilities: SolarWinds, Ivanti, and Critical ICS Exposure 8"></p>
<p><!-- wp:paragraph --></p>
<p>Cyble Research &amp; Intelligence Labs (CRIL) tracked <strong>1,158 vulnerabilities</strong> last week. Of these, <strong>251 vulnerabilities already have publicly available Proof-of-Concept (PoC) exploits</strong>, significantly increasing the likelihood of real-world attacks. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A total of <strong>94 vulnerabilities were rated critical under CVSS v3.1</strong>, while <strong>43 were rated critical under CVSS v4.0</strong>.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>In parallel, CISA issued <strong>15 ICS advisories</strong> covering <strong>87 vulnerabilities</strong> affecting industrial environments. These vulnerabilities impacted vendors including Siemens, Yokogawa, AVEVA, Hitachi Energy, ZLAN, ZOLL, and Airleader. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Additionally, <strong>8 vulnerabilities were added to CISA’s Known Exploited Vulnerabilities (KEV) catalog</strong>, reflecting confirmed exploitation in the wild. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>The Week’s Top Vulnerabilities</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2025-40554 — SolarWinds Web Help Desk (Critical)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2025-40554 is a critical <a href="https://cyble.com/blog/multi-factor-authentication-mfa-is-a-part-of-your-cyber-hygiene/" target="_blank" rel="noreferrer noopener">authentication</a> bypass vulnerability affecting SolarWinds Web Help Desk versions prior to 2026.1. The flaw allows unauthenticated remote attackers to invoke privileged functionality without valid credentials, potentially leading to full compromise of helpdesk systems. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Cyble observed this vulnerability being discussed on underground forums shortly after disclosure, and a public PoC is available. The vulnerability’s presence in enterprise environments increases the risk of initial access and lateral movement. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-1340 — Ivanti Endpoint Manager Mobile (Critical)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-1340 is a critical code injection vulnerability in Ivanti <a href="https://cyble.com/knowledge-hub/what-is-endpoint-security-how-it-works/" target="_blank" rel="noreferrer noopener">Endpoint</a> Manager Mobile (EPMM). A remote, unauthenticated attacker can exploit the flaw to achieve arbitrary remote code execution without user interaction. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The vulnerability has been captured in <a href="https://cyble.com/knowledge-hub/what-is-the-dark-web/" target="_blank" rel="noreferrer noopener">dark web</a> discussions and has a publicly available PoC , significantly lowering the barrier to exploitation. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-21509 — Microsoft Office (High Severity, Actively Exploited)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-21509 is a feature-bypass vulnerability in Microsoft Office that allows crafted documents to circumvent built-in security protections. Attackers can deliver malicious Office files that execute payloads once opened by the victim. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The flaw has been actively exploited by <a href="https://cyble.com/knowledge-hub/cyber-threat-actor-and-types/" target="_blank" rel="noreferrer noopener">threat actors</a> including APT28 and RomCom , highlighting its operational impact. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-1529 — Keycloak (High Impact)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-1529 affects Red Hat’s Keycloak and involves improper validation of JWT invitation token signatures. Attackers can manipulate trusted token contents to gain unauthorized access to organizational resources. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A PoC is available, and the vulnerability surfaced on underground forums shortly after disclosure. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-23906 — Apache Druid (Critical)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-23906 is a critical authentication bypass vulnerability in Apache Druid, enabling unauthorized access to <a href="https://cyble.com/knowledge-hub/what-is-data-loss-prevention/" target="_blank" rel="noreferrer noopener">sensitive data</a> stores. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-0488 — SAP CRM &amp; SAP S/4HANA (Critical)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-0488 is a critical code injection vulnerability affecting SAP CRM and SAP S/4HANA. An authenticated attacker can exploit improper function module calls to execute arbitrary SQL statements, potentially resulting in full database compromise. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Vulnerabilities Added to CISA KEV</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>CISA added 8 vulnerabilities to the KEV catalog during the reporting period. The most important of these were: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>CVE-2026-24423</strong> — SmarterTools SmarterMail unauthenticated RCE </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>CVE-2026-21510</strong> — Microsoft Windows Shell protection mechanism bypass </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>KEV additions reflect confirmed exploitation in the wild and often signal heightened <a href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noreferrer noopener">ransomware</a> or espionage activity. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Critical ICS Vulnerabilities</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>CISA issued <strong>15 ICS advisories</strong> covering <strong>87 vulnerabilities</strong>, with the majority rated high severity. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-25084 &amp; CVE-2026-24789 — ZLAN5143D (Critical)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>These critical vulnerabilities in ZLAN Information Technology Co.’s ZLAN5143D device involve missing authentication for critical functions. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Successful exploitation could allow attackers to bypass authentication controls or reset device passwords, potentially enabling unauthorized configuration changes and interference with industrial communications. Researchers also identified internet-facing instances, increasing exposure risk. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2025-52533 — Siemens SINEC OS (Critical)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2025-52533 is a critical out-of-bounds write vulnerability in Siemens SINEC OS before version 3.3, potentially enabling memory corruption and system compromise in industrial network environments. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-1358 — Airleader Master (Critical)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-1358 is a critical, unrestricted file-upload vulnerability in Airleader Master systems. Successful exploitation could allow attackers to upload malicious files, potentially resulting in remote code execution in OT environments. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Impacted Critical Infrastructure Sectors</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Analysis of the ICS advisories shows that <a href="https://cyble.com/knowledge-hub/supply-chain-security-manufacturing/" target="_blank" rel="noreferrer noopener">Critical Manufacturing and Energy sectors</a> appear in 98.9% of reported vulnerabilities, showcasing concentrated exposure in these environments. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The cross-sector nature of these vulnerabilities underscores the interdependencies between Energy, Manufacturing, Transportation, Water, and Food systems. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Conclusion</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>The convergence of high-volume IT vulnerabilities and significant ICS exposure highlights the continued expansion of the <a href="https://cyble.com/knowledge-hub/attack-surface-management-risk-reduction/" target="_blank" rel="noreferrer noopener">attack surface</a> across enterprise and industrial environments. With over 250 PoCs publicly available and multiple KEV additions confirming active exploitation, organizations must prioritize rapid remediation and risk-based <a href="https://cyble.com/solutions/vulnerability-management/" target="_blank" rel="noreferrer noopener">vulnerability management</a>. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Security best practices include: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Prioritizing vulnerabilities based on risk and exploit availability </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Protecting web-facing and internet-exposed assets </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Implementing strict IT/OT network segmentation </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Deploying multi-factor authentication and strong access controls </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Conducting regular vulnerability assessments and penetration testing </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Monitoring underground forums and KEV updates for early warning signals </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Establishing ransomware-resistant backup strategies </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Maintaining OT-specific incident response procedures </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>Cyble’s comprehensive <a href="https://cyble.com/solutions/attack-surface-management/" target="_blank" rel="noreferrer noopener">attack surface management solutions</a> help organizations continuously monitor internal and external assets, prioritize remediation, and detect early warning signals of exploitation. Additionally, <a href="https://cyble.com/solutions/cyber-threat-intelligence/" target="_blank" rel="noreferrer noopener">Cyble’s threat intelligence</a> and third-party risk intelligence capabilities provide visibility into vulnerabilities actively discussed in underground communities, enabling proactive defense against both IT and ICS threats.</p>
<p><!-- /wp:paragraph --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/cyble-weekly-vulnerability-report-feb-19/">The Week in Vulnerabilities: SolarWinds, Ivanti, and Critical ICS Exposure</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Week in Vulnerabilities: SolarWinds, Ivanti, and Critical ICS Exposure]]></title>
<description><![CDATA[Cyble Research & Intelligence Labs (CRIL) tracked 1,158 vulnerabilities last week. Of these, 251 vulnerabilities already have publicly available Proof-of-Concept (PoC) exploits, significantly increasing the likelihood of real-world attacks. 


A total of 94 vulnerabilities were rated critical und...]]></description>
<link>https://tsecurity.de/de/3346345/it-security-nachrichten/the-week-in-vulnerabilities-solarwinds-ivanti-and-critical-ics-exposure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3346345/it-security-nachrichten/the-week-in-vulnerabilities-solarwinds-ivanti-and-critical-ics-exposure/</guid>
<pubDate>Fri, 13 Mar 2026 12:40:19 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="800" height="400" src="https://cyble.com/wp-content/uploads/2026/02/Cyble-vulnerability-Report-1.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Cyble vulnerability Report" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/02/Cyble-vulnerability-Report-1.webp 800w, https://cyble.com/wp-content/uploads/2026/02/Cyble-vulnerability-Report-1-300x150.webp 300w, https://cyble.com/wp-content/uploads/2026/02/Cyble-vulnerability-Report-1-768x384.webp 768w, https://cyble.com/wp-content/uploads/2026/02/Cyble-vulnerability-Report-1-600x300.webp 600w" sizes="(max-width: 800px) 100vw, 800px" title="The Week in Vulnerabilities: SolarWinds, Ivanti, and Critical ICS Exposure 8"></p>
<p><!-- wp:paragraph --></p>
<p>Cyble Research &amp; Intelligence Labs (CRIL) tracked <strong>1,158 vulnerabilities</strong> last week. Of these, <strong>251 vulnerabilities already have publicly available Proof-of-Concept (PoC) exploits</strong>, significantly increasing the likelihood of real-world attacks. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A total of <strong>94 vulnerabilities were rated critical under CVSS v3.1</strong>, while <strong>43 were rated critical under CVSS v4.0</strong>.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>In parallel, CISA issued <strong>15 ICS advisories</strong> covering <strong>87 vulnerabilities</strong> affecting industrial environments. These vulnerabilities impacted vendors including Siemens, Yokogawa, AVEVA, Hitachi Energy, ZLAN, ZOLL, and Airleader. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Additionally, <strong>8 vulnerabilities were added to CISA’s Known Exploited Vulnerabilities (KEV) catalog</strong>, reflecting confirmed exploitation in the wild. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>The Week’s Top Vulnerabilities</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2025-40554 — SolarWinds Web Help Desk (Critical)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2025-40554 is a critical <a href="https://cyble.com/blog/multi-factor-authentication-mfa-is-a-part-of-your-cyber-hygiene/" target="_blank" rel="noreferrer noopener">authentication</a> bypass vulnerability affecting SolarWinds Web Help Desk versions prior to 2026.1. The flaw allows unauthenticated remote attackers to invoke privileged functionality without valid credentials, potentially leading to full compromise of helpdesk systems. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Cyble observed this vulnerability being discussed on underground forums shortly after disclosure, and a public PoC is available. The vulnerability’s presence in enterprise environments increases the risk of initial access and lateral movement. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-1340 — Ivanti Endpoint Manager Mobile (Critical)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-1340 is a critical code injection vulnerability in Ivanti <a href="https://cyble.com/knowledge-hub/what-is-endpoint-security-how-it-works/" target="_blank" rel="noreferrer noopener">Endpoint</a> Manager Mobile (EPMM). A remote, unauthenticated attacker can exploit the flaw to achieve arbitrary remote code execution without user interaction. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The vulnerability has been captured in <a href="https://cyble.com/knowledge-hub/what-is-the-dark-web/" target="_blank" rel="noreferrer noopener">dark web</a> discussions and has a publicly available PoC , significantly lowering the barrier to exploitation. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-21509 — Microsoft Office (High Severity, Actively Exploited)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-21509 is a feature-bypass vulnerability in Microsoft Office that allows crafted documents to circumvent built-in security protections. Attackers can deliver malicious Office files that execute payloads once opened by the victim. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The flaw has been actively exploited by <a href="https://cyble.com/knowledge-hub/cyber-threat-actor-and-types/" target="_blank" rel="noreferrer noopener">threat actors</a> including APT28 and RomCom , highlighting its operational impact. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-1529 — Keycloak (High Impact)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-1529 affects Red Hat’s Keycloak and involves improper validation of JWT invitation token signatures. Attackers can manipulate trusted token contents to gain unauthorized access to organizational resources. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A PoC is available, and the vulnerability surfaced on underground forums shortly after disclosure. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-23906 — Apache Druid (Critical)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-23906 is a critical authentication bypass vulnerability in Apache Druid, enabling unauthorized access to <a href="https://cyble.com/knowledge-hub/what-is-data-loss-prevention/" target="_blank" rel="noreferrer noopener">sensitive data</a> stores. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-0488 — SAP CRM &amp; SAP S/4HANA (Critical)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-0488 is a critical code injection vulnerability affecting SAP CRM and SAP S/4HANA. An authenticated attacker can exploit improper function module calls to execute arbitrary SQL statements, potentially resulting in full database compromise. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Vulnerabilities Added to CISA KEV</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>CISA added 8 vulnerabilities to the KEV catalog during the reporting period. The most important of these were: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>CVE-2026-24423</strong> — SmarterTools SmarterMail unauthenticated RCE </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>CVE-2026-21510</strong> — Microsoft Windows Shell protection mechanism bypass </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>KEV additions reflect confirmed exploitation in the wild and often signal heightened <a href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noreferrer noopener">ransomware</a> or espionage activity. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Critical ICS Vulnerabilities</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>CISA issued <strong>15 ICS advisories</strong> covering <strong>87 vulnerabilities</strong>, with the majority rated high severity. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-25084 &amp; CVE-2026-24789 — ZLAN5143D (Critical)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>These critical vulnerabilities in ZLAN Information Technology Co.’s ZLAN5143D device involve missing authentication for critical functions. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Successful exploitation could allow attackers to bypass authentication controls or reset device passwords, potentially enabling unauthorized configuration changes and interference with industrial communications. Researchers also identified internet-facing instances, increasing exposure risk. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2025-52533 — Siemens SINEC OS (Critical)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2025-52533 is a critical out-of-bounds write vulnerability in Siemens SINEC OS before version 3.3, potentially enabling memory corruption and system compromise in industrial network environments. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-1358 — Airleader Master (Critical)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-1358 is a critical, unrestricted file-upload vulnerability in Airleader Master systems. Successful exploitation could allow attackers to upload malicious files, potentially resulting in remote code execution in OT environments. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Impacted Critical Infrastructure Sectors</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Analysis of the ICS advisories shows that <a href="https://cyble.com/knowledge-hub/supply-chain-security-manufacturing/" target="_blank" rel="noreferrer noopener">Critical Manufacturing and Energy sectors</a> appear in 98.9% of reported vulnerabilities, showcasing concentrated exposure in these environments. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The cross-sector nature of these vulnerabilities underscores the interdependencies between Energy, Manufacturing, Transportation, Water, and Food systems. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Conclusion</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>The convergence of high-volume IT vulnerabilities and significant ICS exposure highlights the continued expansion of the <a href="https://cyble.com/knowledge-hub/attack-surface-management-risk-reduction/" target="_blank" rel="noreferrer noopener">attack surface</a> across enterprise and industrial environments. With over 250 PoCs publicly available and multiple KEV additions confirming active exploitation, organizations must prioritize rapid remediation and risk-based <a href="https://cyble.com/solutions/vulnerability-management/" target="_blank" rel="noreferrer noopener">vulnerability management</a>. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Security best practices include: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Prioritizing vulnerabilities based on risk and exploit availability </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Protecting web-facing and internet-exposed assets </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Implementing strict IT/OT network segmentation </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Deploying multi-factor authentication and strong access controls </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Conducting regular vulnerability assessments and penetration testing </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Monitoring underground forums and KEV updates for early warning signals </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Establishing ransomware-resistant backup strategies </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Maintaining OT-specific incident response procedures </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>Cyble’s comprehensive <a href="https://cyble.com/solutions/attack-surface-management/" target="_blank" rel="noreferrer noopener">attack surface management solutions</a> help organizations continuously monitor internal and external assets, prioritize remediation, and detect early warning signals of exploitation. Additionally, <a href="https://cyble.com/solutions/cyber-threat-intelligence/" target="_blank" rel="noreferrer noopener">Cyble’s threat intelligence</a> and third-party risk intelligence capabilities provide visibility into vulnerabilities actively discussed in underground communities, enabling proactive defense against both IT and ICS threats.</p>
<p><!-- /wp:paragraph --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/blog/cyble-weekly-vulnerability-report-feb-19/">The Week in Vulnerabilities: SolarWinds, Ivanti, and Critical ICS Exposure</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-66594 | Yokogawa Electric FAST TOOLS up to R10.04 Detailed Message information exposure]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Yokogawa Electric FAST TOOLS up to R10.04. This affects an unknown function of the component Detailed Message Handler. The manipulation results in information exposure through error message.

This vulnerability is identified as CVE-2025-66594...]]></description>
<link>https://tsecurity.de/de/3331260/sicherheitsluecken/cve-2025-66594-yokogawa-electric-fast-tools-up-to-r1004-detailed-message-information-exposure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3331260/sicherheitsluecken/cve-2025-66594-yokogawa-electric-fast-tools-up-to-r1004-detailed-message-information-exposure/</guid>
<pubDate>Fri, 06 Mar 2026 22:51:15 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">problematic</a> was found in <a href="https://vuldb.com/?product.yokogawa_electric:fast_tools">Yokogawa Electric FAST TOOLS up to R10.04</a>. This affects an unknown function of the component <em>Detailed Message Handler</em>. The manipulation results in information exposure through error message.

This vulnerability is identified as <a href="https://vuldb.com/?source_cve.344947">CVE-2025-66594</a>. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-66608 | Yokogawa Electric FAST TOOLS up to R10.04 Requests path traversal]]></title>
<description><![CDATA[A vulnerability was found in Yokogawa Electric FAST TOOLS up to R10.04. It has been declared as problematic. This vulnerability affects unknown code of the component Requests Handler. The manipulation results in path traversal: '\..\filename'.

This vulnerability is reported as CVE-2025-66608. Th...]]></description>
<link>https://tsecurity.de/de/3331259/sicherheitsluecken/cve-2025-66608-yokogawa-electric-fast-tools-up-to-r1004-requests-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3331259/sicherheitsluecken/cve-2025-66608-yokogawa-electric-fast-tools-up-to-r1004-requests-path-traversal/</guid>
<pubDate>Fri, 06 Mar 2026 22:51:14 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.yokogawa_electric:fast_tools">Yokogawa Electric FAST TOOLS up to R10.04</a>. It has been declared as <a href="https://vuldb.com/?kb.risk">problematic</a>. This vulnerability affects unknown code of the component <em>Requests Handler</em>. The manipulation results in path traversal: '\..\filename'.

This vulnerability is reported as <a href="https://vuldb.com/?source_cve.344953">CVE-2025-66608</a>. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-66597 | Yokogawa Electric FAST TOOLS up to R10.04 risky encryption]]></title>
<description><![CDATA[A vulnerability was found in Yokogawa Electric FAST TOOLS up to R10.04. It has been rated as problematic. This issue affects some unknown processing. This manipulation causes risky cryptographic algorithm.

This vulnerability appears as CVE-2025-66597. The attack may be initiated remotely. There ...]]></description>
<link>https://tsecurity.de/de/3331258/sicherheitsluecken/cve-2025-66597-yokogawa-electric-fast-tools-up-to-r1004-risky-encryption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3331258/sicherheitsluecken/cve-2025-66597-yokogawa-electric-fast-tools-up-to-r1004-risky-encryption/</guid>
<pubDate>Fri, 06 Mar 2026 22:51:13 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.yokogawa_electric:fast_tools">Yokogawa Electric FAST TOOLS up to R10.04</a>. It has been rated as <a href="https://vuldb.com/?kb.risk">problematic</a>. This issue affects some unknown processing. This manipulation causes risky cryptographic algorithm.

This vulnerability appears as <a href="https://vuldb.com/?source_cve.344954">CVE-2025-66597</a>. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-66607 | Yokogawa Electric FAST TOOLS up to R10.04 security check]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Yokogawa Electric FAST TOOLS up to R10.04. Impacted is an unknown function. Such manipulation leads to security check for standard.

This vulnerability is traded as CVE-2025-66607. The attack may be launched remotely. There is no e...]]></description>
<link>https://tsecurity.de/de/3331257/sicherheitsluecken/cve-2025-66607-yokogawa-electric-fast-tools-up-to-r1004-security-check/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3331257/sicherheitsluecken/cve-2025-66607-yokogawa-electric-fast-tools-up-to-r1004-security-check/</guid>
<pubDate>Fri, 06 Mar 2026 22:51:12 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/?kb.risk">problematic</a> has been discovered in <a href="https://vuldb.com/?product.yokogawa_electric:fast_tools">Yokogawa Electric FAST TOOLS up to R10.04</a>. Impacted is an unknown function. Such manipulation leads to security check for standard.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.344955">CVE-2025-66607</a>. The attack may be launched remotely. There is no exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-66596 | Yokogawa Electric FAST TOOLS up to R10.04 Request Header redirect]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Yokogawa Electric FAST TOOLS up to R10.04. The affected element is an unknown function of the component Request Header Handler. Performing a manipulation results in open redirect.

This vulnerability is known as CVE-2025-66596. Remote...]]></description>
<link>https://tsecurity.de/de/3331256/sicherheitsluecken/cve-2025-66596-yokogawa-electric-fast-tools-up-to-r1004-request-header-redirect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3331256/sicherheitsluecken/cve-2025-66596-yokogawa-electric-fast-tools-up-to-r1004-request-header-redirect/</guid>
<pubDate>Fri, 06 Mar 2026 22:51:10 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/?kb.risk">problematic</a> has been detected in <a href="https://vuldb.com/?product.yokogawa_electric:fast_tools">Yokogawa Electric FAST TOOLS up to R10.04</a>. The affected element is an unknown function of the component <em>Request Header Handler</em>. Performing a manipulation results in open redirect.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.344956">CVE-2025-66596</a>. Remote exploitation of the attack is possible. No exploit is available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-66598 | Yokogawa Electric FAST TOOLS up to R10.04 SSL/TLS risky encryption]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Yokogawa Electric FAST TOOLS up to R10.04. The impacted element is an unknown function of the component SSL/TLS. Executing a manipulation can lead to risky cryptographic algorithm.

This vulnerability is handled as CVE-2025-66598. The attac...]]></description>
<link>https://tsecurity.de/de/3331255/sicherheitsluecken/cve-2025-66598-yokogawa-electric-fast-tools-up-to-r1004-ssltls-risky-encryption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3331255/sicherheitsluecken/cve-2025-66598-yokogawa-electric-fast-tools-up-to-r1004-ssltls-risky-encryption/</guid>
<pubDate>Fri, 06 Mar 2026 22:51:09 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/?kb.risk">problematic</a> has been found in <a href="https://vuldb.com/?product.yokogawa_electric:fast_tools">Yokogawa Electric FAST TOOLS up to R10.04</a>. The impacted element is an unknown function of the component <em>SSL/TLS</em>. Executing a manipulation can lead to risky cryptographic algorithm.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.344957">CVE-2025-66598</a>. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-66595 | Yokogawa Electric FAST TOOLS up to R10.04 cross-site request forgery]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Yokogawa Electric FAST TOOLS up to R10.04. This impacts an unknown function. The manipulation results in cross-site request forgery.

This vulnerability was named CVE-2025-66595. The attack may be performed from remote. There is no a...]]></description>
<link>https://tsecurity.de/de/3331253/sicherheitsluecken/cve-2025-66595-yokogawa-electric-fast-tools-up-to-r1004-cross-site-request-forgery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3331253/sicherheitsluecken/cve-2025-66595-yokogawa-electric-fast-tools-up-to-r1004-cross-site-request-forgery/</guid>
<pubDate>Fri, 06 Mar 2026 22:51:06 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/?kb.risk">problematic</a> has been identified in <a href="https://vuldb.com/?product.yokogawa_electric:fast_tools">Yokogawa Electric FAST TOOLS up to R10.04</a>. This impacts an unknown function. The manipulation results in cross-site request forgery.

This vulnerability was named <a href="https://vuldb.com/?source_cve.344959">CVE-2025-66595</a>. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-66604 | Yokogawa Electric FAST TOOLS up to R10.04 cleartext transmission]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in Yokogawa Electric FAST TOOLS up to R10.04. The impacted element is an unknown function. The manipulation leads to cleartext transmission of sensitive information.

This vulnerability is referenced as CVE-2025-66604. Remote exploitation o...]]></description>
<link>https://tsecurity.de/de/3328043/sicherheitsluecken/cve-2025-66604-yokogawa-electric-fast-tools-up-to-r1004-cleartext-transmission/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3328043/sicherheitsluecken/cve-2025-66604-yokogawa-electric-fast-tools-up-to-r1004-cleartext-transmission/</guid>
<pubDate>Thu, 05 Mar 2026 15:07:28 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">problematic</a> has been found in <a href="https://vuldb.com/?product.yokogawa_electric:fast_tools">Yokogawa Electric FAST TOOLS up to R10.04</a>. The impacted element is an unknown function. The manipulation leads to cleartext transmission of sensitive information.

This vulnerability is referenced as <a href="https://vuldb.com/?source_cve.344946">CVE-2025-66604</a>. Remote exploitation of the attack is possible. No exploit is available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-66603 | Yokogawa Electric FAST TOOLS up to R10.04 OPTIONS Method security check]]></title>
<description><![CDATA[A vulnerability has been found in Yokogawa Electric FAST TOOLS up to R10.04 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component OPTIONS Method Handler. Performing a manipulation results in security check for standard.

This vulnerability is c...]]></description>
<link>https://tsecurity.de/de/3328042/sicherheitsluecken/cve-2025-66603-yokogawa-electric-fast-tools-up-to-r1004-options-method-security-check/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3328042/sicherheitsluecken/cve-2025-66603-yokogawa-electric-fast-tools-up-to-r1004-options-method-security-check/</guid>
<pubDate>Thu, 05 Mar 2026 15:07:27 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/?product.yokogawa_electric:fast_tools">Yokogawa Electric FAST TOOLS up to R10.04</a> and classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. Affected by this vulnerability is an unknown functionality of the component <em>OPTIONS Method Handler</em>. Performing a manipulation results in security check for standard.

This vulnerability is cataloged as <a href="https://vuldb.com/?source_cve.344950">CVE-2025-66603</a>. It is possible to initiate the attack remotely. There is no exploit available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-66606 | Yokogawa Electric FAST TOOLS up to R10.04 cross site scripting]]></title>
<description><![CDATA[A vulnerability was found in Yokogawa Electric FAST TOOLS up to R10.04. It has been classified as problematic. This affects an unknown part. The manipulation leads to improper neutralization of invalid characters in identifiers in web pages.

This vulnerability is documented as CVE-2025-66606. Th...]]></description>
<link>https://tsecurity.de/de/3328041/sicherheitsluecken/cve-2025-66606-yokogawa-electric-fast-tools-up-to-r1004-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3328041/sicherheitsluecken/cve-2025-66606-yokogawa-electric-fast-tools-up-to-r1004-cross-site-scripting/</guid>
<pubDate>Thu, 05 Mar 2026 15:07:26 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.yokogawa_electric:fast_tools">Yokogawa Electric FAST TOOLS up to R10.04</a>. It has been classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. This affects an unknown part. The manipulation leads to improper neutralization of invalid characters in identifiers in web pages.

This vulnerability is documented as <a href="https://vuldb.com/?source_cve.344952">CVE-2025-66606</a>. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-66605 | Yokogawa Electric FAST TOOLS up to R10.04 private personal information]]></title>
<description><![CDATA[A vulnerability was found in Yokogawa Electric FAST TOOLS up to R10.04 and classified as problematic. Affected by this issue is some unknown functionality. Executing a manipulation can lead to exposure of private personal information to an unauthorized actor.

This vulnerability is registered as ...]]></description>
<link>https://tsecurity.de/de/3328040/sicherheitsluecken/cve-2025-66605-yokogawa-electric-fast-tools-up-to-r1004-private-personal-information/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3328040/sicherheitsluecken/cve-2025-66605-yokogawa-electric-fast-tools-up-to-r1004-private-personal-information/</guid>
<pubDate>Thu, 05 Mar 2026 15:07:24 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.yokogawa_electric:fast_tools">Yokogawa Electric FAST TOOLS up to R10.04</a> and classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. Affected by this issue is some unknown functionality. Executing a manipulation can lead to exposure of private personal information to an unauthorized actor.

This vulnerability is registered as <a href="https://vuldb.com/?source_cve.344951">CVE-2025-66605</a>. It is possible to launch the attack remotely. No exploit is available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-66602 | Yokogawa Electric FAST TOOLS up to R10.04 ip address for authentication]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Yokogawa Electric FAST TOOLS up to R10.04. Affected is an unknown function. Such manipulation leads to reliance on ip address for authentication.

This vulnerability is listed as CVE-2025-66602. The attack may be performed from re...]]></description>
<link>https://tsecurity.de/de/3328039/sicherheitsluecken/cve-2025-66602-yokogawa-electric-fast-tools-up-to-r1004-ip-address-for-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3328039/sicherheitsluecken/cve-2025-66602-yokogawa-electric-fast-tools-up-to-r1004-ip-address-for-authentication/</guid>
<pubDate>Thu, 05 Mar 2026 15:07:23 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, was found in <a href="https://vuldb.com/?product.yokogawa_electric:fast_tools">Yokogawa Electric FAST TOOLS up to R10.04</a>. Affected is an unknown function. Such manipulation leads to reliance on ip address for authentication.

This vulnerability is listed as <a href="https://vuldb.com/?source_cve.344949">CVE-2025-66602</a>. The attack may be performed from remote. There is no available exploit.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-66601 | Yokogawa Electric FAST TOOLS up to R10.04 security check]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Yokogawa Electric FAST TOOLS up to R10.04. This impacts an unknown function. This manipulation causes security check for standard.

This vulnerability is tracked as CVE-2025-66601. The attack is possible to be carried out remote...]]></description>
<link>https://tsecurity.de/de/3328037/sicherheitsluecken/cve-2025-66601-yokogawa-electric-fast-tools-up-to-r1004-security-check/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3328037/sicherheitsluecken/cve-2025-66601-yokogawa-electric-fast-tools-up-to-r1004-security-check/</guid>
<pubDate>Thu, 05 Mar 2026 15:07:20 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, has been found in <a href="https://vuldb.com/?product.yokogawa_electric:fast_tools">Yokogawa Electric FAST TOOLS up to R10.04</a>. This impacts an unknown function. This manipulation causes security check for standard.

This vulnerability is tracked as <a href="https://vuldb.com/?source_cve.344948">CVE-2025-66601</a>. The attack is possible to be carried out remotely. No exploit exists.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-48022 | Yokogawa Electric Vnet-IP Interface Package up to 1.07.00 length parameter]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Yokogawa Electric Vnet-IP Interface Package up to 1.07.00. This impacts an unknown function. This manipulation causes improper handling of length parameter inconsistency.

This vulnerability is handled as CVE-2025-48022. The ...]]></description>
<link>https://tsecurity.de/de/3321481/sicherheitsluecken/cve-2025-48022-yokogawa-electric-vnet-ip-interface-package-up-to-10700-length-parameter/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3321481/sicherheitsluecken/cve-2025-48022-yokogawa-electric-vnet-ip-interface-package-up-to-10700-length-parameter/</guid>
<pubDate>Tue, 03 Mar 2026 04:20:49 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, has been found in <a href="https://vuldb.com/?product.yokogawa_electric:vnet-ip_interface_package">Yokogawa Electric Vnet-IP Interface Package up to 1.07.00</a>. This impacts an unknown function. This manipulation causes improper handling of length parameter inconsistency.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.345872">CVE-2025-48022</a>. The attack can only be done within the local network. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-48023 | Yokogawa Electric Vnet-IP Interface Package up to 1.07.00 assertion]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Yokogawa Electric Vnet-IP Interface Package up to 1.07.00. Impacted is an unknown function. Performing a manipulation results in reachable assertion.

This vulnerability is reported as CVE-2025-48023. The attacker must have access to the ...]]></description>
<link>https://tsecurity.de/de/3321477/sicherheitsluecken/cve-2025-48023-yokogawa-electric-vnet-ip-interface-package-up-to-10700-assertion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3321477/sicherheitsluecken/cve-2025-48023-yokogawa-electric-vnet-ip-interface-package-up-to-10700-assertion/</guid>
<pubDate>Tue, 03 Mar 2026 04:20:44 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/?kb.risk">problematic</a> has been reported in <a href="https://vuldb.com/?product.yokogawa_electric:vnet-ip_interface_package">Yokogawa Electric Vnet-IP Interface Package up to 1.07.00</a>. Impacted is an unknown function. Performing a manipulation results in reachable assertion.

This vulnerability is reported as <a href="https://vuldb.com/?source_cve.345868">CVE-2025-48023</a>. The attacker must have access to the local network to execute the attack. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-48021 | Yokogawa Electric Vnet-IP Interface Package up to 1.07.00 integer underflow]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Yokogawa Electric Vnet-IP Interface Package up to 1.07.00. The affected element is an unknown function. Executing a manipulation can lead to integer underflow.

This vulnerability appears as CVE-2025-48021. The attacker needs to be p...]]></description>
<link>https://tsecurity.de/de/3321476/sicherheitsluecken/cve-2025-48021-yokogawa-electric-vnet-ip-interface-package-up-to-10700-integer-underflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3321476/sicherheitsluecken/cve-2025-48021-yokogawa-electric-vnet-ip-interface-package-up-to-10700-integer-underflow/</guid>
<pubDate>Tue, 03 Mar 2026 04:20:42 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/?kb.risk">problematic</a> has been identified in <a href="https://vuldb.com/?product.yokogawa_electric:vnet-ip_interface_package">Yokogawa Electric Vnet-IP Interface Package up to 1.07.00</a>. The affected element is an unknown function. Executing a manipulation can lead to integer underflow.

This vulnerability appears as <a href="https://vuldb.com/?source_cve.345869">CVE-2025-48021</a>. The attacker needs to be present on the local network. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa CENTUM VP R6, R7]]></title>
<description><![CDATA[View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to terminate the software stack process, cause a denial-of-service condition, or execute arbitrary code.
The following versions of Yokogawa CENTUM VP R6, R7 are affected:

Vnet/IP Interface Package for CENT...]]></description>
<link>https://tsecurity.de/de/3313059/it-security-nachrichten/yokogawa-centum-vp-r6-r7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3313059/it-security-nachrichten/yokogawa-centum-vp-r6-r7/</guid>
<pubDate>Thu, 26 Feb 2026 19:05:57 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-057-09.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to terminate the software stack process, cause a denial-of-service condition, or execute arbitrary code.</strong></p>
<p>The following versions of Yokogawa CENTUM VP R6, R7 are affected:</p>
<ul>
<li>Vnet/IP Interface Package for CENTUM VP R6 (VP6C3300) &lt;=R1.07.00 (CVE-2025-1924, CVE-2025-48019, CVE-2025-48020, CVE-2025-48021, CVE-2025-48022, CVE-2025-48023)</li>
<li>Vnet/IP Interface Package for CENTUM VP R7 (VP7C3300) &lt;=R1.07.00 (CVE-2025-1924, CVE-2025-48019, CVE-2025-48020, CVE-2025-48021, CVE-2025-48022, CVE-2025-48023)</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 6.9</td>
<td>Yokogawa</td>
<td>Yokogawa CENTUM VP R6, R7</td>
<td>Out-of-bounds Write, Reachable Assertion, Integer Underflow (Wrap or Wraparound), Improper Handling of Length Parameter Inconsistency</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy, Food and Agriculture</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Japan</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-1924</a></h3>
<div class="csaf-accordion-content">
<p>If the affected product receives maliciously crafted packets, a DoS attack may cause Vnet/IP communication functions to stop or arbitrary programs to be executed.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1924">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa CENTUM VP R6, R7</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa Vnet/IP Interface Package for CENTUM VP R6 (VP6C3300): &lt;=R1.07.00, Yokogawa Vnet/IP Interface Package for CENTUM VP R7 (VP7C3300): &lt;=R1.07.00</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users apply patch software (R1.08.00).</p>
<p><strong>Mitigation</strong><br>Yokogawa recommends users contact a local supporting office for further information or support. https://contact.yokogawa.com/cs/gw?c-id=000498</p>
<p><strong>Mitigation</strong><br>For more information and details on implementing these mitigations, users should see the Yokogawa advisory YSAR-26-0002 at https://web-material3.yokogawa.com/1/39281/files/YSAR-26-0002-E.pdf</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.9</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H">CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-48019</a></h3>
<div class="csaf-accordion-content">
<p>If the affected product receives maliciously crafted packets, Vnet/IP software stack process may be terminated.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48019">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa CENTUM VP R6, R7</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa Vnet/IP Interface Package for CENTUM VP R6 (VP6C3300): &lt;=R1.07.00, Yokogawa Vnet/IP Interface Package for CENTUM VP R7 (VP7C3300): &lt;=R1.07.00</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users apply patch software (R1.08.00).</p>
<p><strong>Mitigation</strong><br>Yokogawa recommends users contact a local supporting office for further information or support. https://contact.yokogawa.com/cs/gw?c-id=000498</p>
<p><strong>Mitigation</strong><br>For more information and details on implementing these mitigations, users should see the Yokogawa advisory YSAR-26-0002 at https://web-material3.yokogawa.com/1/39281/files/YSAR-26-0002-E.pdf</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/617.html">CWE-617 Reachable Assertion</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-48020</a></h3>
<div class="csaf-accordion-content">
<p>If the affected product receives maliciously crafted packets, Vnet/IP software stack process may be terminated.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48020">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa CENTUM VP R6, R7</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa Vnet/IP Interface Package for CENTUM VP R6 (VP6C3300): &lt;=R1.07.00, Yokogawa Vnet/IP Interface Package for CENTUM VP R7 (VP7C3300): &lt;=R1.07.00</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users apply patch software (R1.08.00).</p>
<p><strong>Mitigation</strong><br>Yokogawa recommends users contact a local supporting office for further information or support. https://contact.yokogawa.com/cs/gw?c-id=000498</p>
<p><strong>Mitigation</strong><br>For more information and details on implementing these mitigations, users should see the Yokogawa advisory YSAR-26-0002 at https://web-material3.yokogawa.com/1/39281/files/YSAR-26-0002-E.pdf</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/617.html">CWE-617 Reachable Assertion</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-48021</a></h3>
<div class="csaf-accordion-content">
<p>If theaffected product receives maliciously crafted packets, Vnet/IP software stack process may be terminated.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48021">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa CENTUM VP R6, R7</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa Vnet/IP Interface Package for CENTUM VP R6 (VP6C3300): &lt;=R1.07.00, Yokogawa Vnet/IP Interface Package for CENTUM VP R7 (VP7C3300): &lt;=R1.07.00</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users apply patch software (R1.08.00).</p>
<p><strong>Mitigation</strong><br>Yokogawa recommends users contact a local supporting office for further information or support. https://contact.yokogawa.com/cs/gw?c-id=000498</p>
<p><strong>Mitigation</strong><br>For more information and details on implementing these mitigations, users should see the Yokogawa advisory YSAR-26-0002 at https://web-material3.yokogawa.com/1/39281/files/YSAR-26-0002-E.pdf</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/191.html">CWE-191 Integer Underflow (Wrap or Wraparound)</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-48022</a></h3>
<div class="csaf-accordion-content">
<p>If the affected product receives maliciously crafted packets, Vnet/IP software stack process may be terminated.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48022">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa CENTUM VP R6, R7</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa Vnet/IP Interface Package for CENTUM VP R6 (VP6C3300): &lt;=R1.07.00, Yokogawa Vnet/IP Interface Package for CENTUM VP R7 (VP7C3300): &lt;=R1.07.00</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users apply patch software (R1.08.00).</p>
<p><strong>Mitigation</strong><br>Yokogawa recommends users contact a local supporting office for further information or support. https://contact.yokogawa.com/cs/gw?c-id=000498</p>
<p><strong>Mitigation</strong><br>For more information and details on implementing these mitigations, users should see the Yokogawa advisory YSAR-26-0002 at https://web-material3.yokogawa.com/1/39281/files/YSAR-26-0002-E.pdf</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/130.html">CWE-130 Improper Handling of Length Parameter Inconsistency</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-48023</a></h3>
<div class="csaf-accordion-content">
<p>If the affected product receives maliciously crafted packets, Vnet/IP software stack process may be terminated.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48023">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa CENTUM VP R6, R7</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa Vnet/IP Interface Package for CENTUM VP R6 (VP6C3300): &lt;=R1.07.00, Yokogawa Vnet/IP Interface Package for CENTUM VP R7 (VP7C3300): &lt;=R1.07.00</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users apply patch software (R1.08.00).</p>
<p><strong>Mitigation</strong><br>Yokogawa recommends users contact a local supporting office for further information or support. https://contact.yokogawa.com/cs/gw?c-id=000498</p>
<p><strong>Mitigation</strong><br>For more information and details on implementing these mitigations, users should see the Yokogawa advisory YSAR-26-0002 at https://web-material3.yokogawa.com/1/39281/files/YSAR-26-0002-E.pdf</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/617.html">CWE-617 Reachable Assertion</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Dmitry Sklyar and Demid Uzenkov of Positive Technologies reported these vulnerabilities to Yokogawa</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>
<p>Do not click web links or open attachments in unsolicited email messages.</p>
<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>
<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>
<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely. These vulnerabilities have a high attack complexity.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-02-26</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-02-26</td>
<td>1</td>
<td>Initial Republication of YSAR-26-0002</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa CENTUM VP R6, R7]]></title>
<description><![CDATA[View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to terminate the software stack process, cause a denial-of-service condition, or execute arbitrary code. The following versions of Yokogawa CENTUM VP R6, R7 are affected: Vnet/IP Interface Package…
Read mor...]]></description>
<link>https://tsecurity.de/de/3313043/it-security-nachrichten/yokogawa-centum-vp-r6-r7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3313043/it-security-nachrichten/yokogawa-centum-vp-r6-r7/</guid>
<pubDate>Thu, 26 Feb 2026 19:05:36 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to terminate the software stack process, cause a denial-of-service condition, or execute arbitrary code. The following versions of Yokogawa CENTUM VP R6, R7 are affected: Vnet/IP Interface Package…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/yokogawa-centum-vp-r6-r7/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/yokogawa-centum-vp-r6-r7/">Yokogawa CENTUM VP R6, R7</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-48019 | Yokogawa Electric Vnet-IP Interface Package up to 1.07.00 Vnet/IP assertion (CNNVD-202602-2302)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Yokogawa Electric Vnet-IP Interface Package up to 1.07.00. This affects an unknown part of the file Vnet/IP. The manipulation results in reachable assertion.

This vulnerability is cataloged as CVE-2025-48019. The attack must origi...]]></description>
<link>https://tsecurity.de/de/3288658/sicherheitsluecken/cve-2025-48019-yokogawa-electric-vnet-ip-interface-package-up-to-10700-vnetip-assertion-cnnvd-202602-2302/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3288658/sicherheitsluecken/cve-2025-48019-yokogawa-electric-vnet-ip-interface-package-up-to-10700-vnetip-assertion-cnnvd-202602-2302/</guid>
<pubDate>Sat, 14 Feb 2026 21:04:45 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/?kb.risk">problematic</a> has been discovered in <a href="https://vuldb.com/?product.yokogawa_electric:vnet-ip_interface_package">Yokogawa Electric Vnet-IP Interface Package up to 1.07.00</a>. This affects an unknown part of the file <em>Vnet/IP</em>. The manipulation results in reachable assertion.

This vulnerability is cataloged as <a href="https://vuldb.com/?source_cve.345865">CVE-2025-48019</a>. The attack must originate from the local network. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-48020 | Yokogawa Electric Vnet-IP Interface Package up to 1.07.00 assertion (CNNVD-202602-2301)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Yokogawa Electric Vnet-IP Interface Package up to 1.07.00. This vulnerability affects unknown code. This manipulation causes reachable assertion.

This vulnerability is registered as CVE-2025-48020. The attack requires access to the l...]]></description>
<link>https://tsecurity.de/de/3288657/sicherheitsluecken/cve-2025-48020-yokogawa-electric-vnet-ip-interface-package-up-to-10700-assertion-cnnvd-202602-2301/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3288657/sicherheitsluecken/cve-2025-48020-yokogawa-electric-vnet-ip-interface-package-up-to-10700-assertion-cnnvd-202602-2301/</guid>
<pubDate>Sat, 14 Feb 2026 21:04:44 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/?kb.risk">problematic</a> has been detected in <a href="https://vuldb.com/?product.yokogawa_electric:vnet-ip_interface_package">Yokogawa Electric Vnet-IP Interface Package up to 1.07.00</a>. This vulnerability affects unknown code. This manipulation causes reachable assertion.

This vulnerability is registered as <a href="https://vuldb.com/?source_cve.345866">CVE-2025-48020</a>. The attack requires access to the local network. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-1924 | Yokogawa Electric Vnet-IP Interface Package up to 1.07.00 integer underflow (CNNVD-202602-2303)]]></title>
<description><![CDATA[A vulnerability was found in Yokogawa Electric Vnet-IP Interface Package up to 1.07.00. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to integer underflow.

This vulnerability is listed as CVE-2025-1924. The attack must be carried o...]]></description>
<link>https://tsecurity.de/de/3288655/sicherheitsluecken/cve-2025-1924-yokogawa-electric-vnet-ip-interface-package-up-to-10700-integer-underflow-cnnvd-202602-2303/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3288655/sicherheitsluecken/cve-2025-1924-yokogawa-electric-vnet-ip-interface-package-up-to-10700-integer-underflow-cnnvd-202602-2303/</guid>
<pubDate>Sat, 14 Feb 2026 21:04:42 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.yokogawa_electric:vnet-ip_interface_package">Yokogawa Electric Vnet-IP Interface Package up to 1.07.00</a>. It has been rated as <a href="https://vuldb.com/?kb.risk">problematic</a>. Affected by this issue is some unknown functionality. The manipulation leads to integer underflow.

This vulnerability is listed as <a href="https://vuldb.com/?source_cve.345864">CVE-2025-1924</a>. The attack must be carried out from within the local network. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa FAST/TOOLS]]></title>
<description><![CDATA[View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to redirected users to malicious sites, decrypt communications, perform a man-in-the-middle (MITM) attack, execute malicious scripts, steal files, and perform other various attacks.
The following versions o...]]></description>
<link>https://tsecurity.de/de/3279957/it-security-nachrichten/yokogawa-fasttools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3279957/it-security-nachrichten/yokogawa-fasttools/</guid>
<pubDate>Tue, 10 Feb 2026 18:37:58 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-041-01.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to redirected users to malicious sites, decrypt communications, perform a man-in-the-middle (MITM) attack, execute malicious scripts, steal files, and perform other various attacks.</strong></p>
<p>The following versions of Yokogawa FAST/TOOLS are affected:</p>
<ul>
<li>FAST/TOOLS &gt;=R9.01|&lt;=R10.04 (CVE-2025-66594, CVE-2025-66595, CVE-2025-66597, CVE-2025-66598, CVE-2025-66599, CVE-2025-66600, CVE-2025-66601, CVE-2025-66602, CVE-2025-66603, CVE-2025-66604, CVE-2025-66605, CVE-2025-66606, CVE-2025-66607, CVE-2025-66608)</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 8.2</td>
<td>Yokogawa</td>
<td>Yokogawa FAST/TOOLS</td>
<td>Generation of Error Message Containing Sensitive Information, Cross-Site Request Forgery (CSRF), Use of a Broken or Risky Cryptographic Algorithm, Exposure of Sensitive System Information to an Unauthorized Control Sphere, Improperly Implemented Security Check for Standard, Reliance on IP Address for Authentication, Cleartext Transmission of Sensitive Information, Exposure of Private Personal Information to an Unauthorized Actor, Improper Neutralization of Invalid Characters in Identifiers in Web Pages, Path Traversal: '\..\filename'</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy, Food and Agriculture</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Japan</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66594</a></h3>
<div class="csaf-accordion-content">
<p>Detailed messages are displayed on the error page. This information could be exploited by an attacker for other attacks.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66594">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa FAST/TOOLS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa FAST/TOOLS: &gt;=R9.01|&lt;=R10.04</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users update to revision R10.04 and apply patch software (CS_e12787). After the patch is applied, users should apply R10.04 SP3.</p>
<p><strong>Mitigation</strong><br>Yokogawa strongly recommends that all users establish and maintain a comprehensive security program, not just for addressing the vulnerability identified in this YSAR. Security program components include patch updates, antivirus software, backup and recovery solutions, zoning, hardening, whitelisting, firewalls, and other related measures. Yokogawa can assist organizations in setting up and continuously maintaining a security program. As a starting point for developing the most effective risk mitigation plan, Yokogawa offers security risk assessment services.</p>
<p><strong>Mitigation</strong><br>For questions related to this report, please contact Yokogawa https://contact.yokogawa.com/cs/gw?c-id=000498.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/209.html">CWE-209 Generation of Error Message Containing Sensitive Information</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66595</a></h3>
<div class="csaf-accordion-content">
<p>This product is vulnerable to cross-site request forgery (CSRF). When a user accesses a link crafted by an attacker, the user's account could be compromised.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66595">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa FAST/TOOLS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa FAST/TOOLS: &gt;=R9.01|&lt;=R10.04</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users update to revision R10.04 and apply patch software (CS_e12787). After the patch is applied, users should apply R10.04 SP3.</p>
<p><strong>Mitigation</strong><br>Yokogawa strongly recommends that all users establish and maintain a comprehensive security program, not just for addressing the vulnerability identified in this YSAR. Security program components include patch updates, antivirus software, backup and recovery solutions, zoning, hardening, whitelisting, firewalls, and other related measures. Yokogawa can assist organizations in setting up and continuously maintaining a security program. As a starting point for developing the most effective risk mitigation plan, Yokogawa offers security risk assessment services.</p>
<p><strong>Mitigation</strong><br>For questions related to this report, please contact Yokogawa https://contact.yokogawa.com/cs/gw?c-id=000498.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/352.html">CWE-352 Cross-Site Request Forgery (CSRF)</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66597</a></h3>
<div class="csaf-accordion-content">
<p>This product supports weak cryptographic algorithms, potentially allowing an attacker to decrypt communications with the web server.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66597">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa FAST/TOOLS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa FAST/TOOLS: &gt;=R9.01|&lt;=R10.04</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users update to revision R10.04 and apply patch software (CS_e12787). After the patch is applied, users should apply R10.04 SP3.</p>
<p><strong>Mitigation</strong><br>Yokogawa strongly recommends that all users establish and maintain a comprehensive security program, not just for addressing the vulnerability identified in this YSAR. Security program components include patch updates, antivirus software, backup and recovery solutions, zoning, hardening, whitelisting, firewalls, and other related measures. Yokogawa can assist organizations in setting up and continuously maintaining a security program. As a starting point for developing the most effective risk mitigation plan, Yokogawa offers security risk assessment services.</p>
<p><strong>Mitigation</strong><br>For questions related to this report, please contact Yokogawa https://contact.yokogawa.com/cs/gw?c-id=000498.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/327.html">CWE-327 Use of a Broken or Risky Cryptographic Algorithm</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.2</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66598</a></h3>
<div class="csaf-accordion-content">
<p>This product supports old SSL/TLS versions, potentially allowing an attacker to decrypt communications with the web server.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66598">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa FAST/TOOLS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa FAST/TOOLS: &gt;=R9.01|&lt;=R10.04</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users update to revision R10.04 and apply patch software (CS_e12787). After the patch is applied, users should apply R10.04 SP3.</p>
<p><strong>Mitigation</strong><br>Yokogawa strongly recommends that all users establish and maintain a comprehensive security program, not just for addressing the vulnerability identified in this YSAR. Security program components include patch updates, antivirus software, backup and recovery solutions, zoning, hardening, whitelisting, firewalls, and other related measures. Yokogawa can assist organizations in setting up and continuously maintaining a security program. As a starting point for developing the most effective risk mitigation plan, Yokogawa offers security risk assessment services.</p>
<p><strong>Mitigation</strong><br>For questions related to this report, please contact Yokogawa https://contact.yokogawa.com/cs/gw?c-id=000498.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/327.html">CWE-327 Use of a Broken or Risky Cryptographic Algorithm</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66599</a></h3>
<div class="csaf-accordion-content">
<p>Physical paths could be displayed on web pages. This information could be exploited by an attacker for other attacks.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66599">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa FAST/TOOLS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa FAST/TOOLS: &gt;=R9.01|&lt;=R10.04</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users update to revision R10.04 and apply patch software (CS_e12787). After the patch is applied, users should apply R10.04 SP3.</p>
<p><strong>Mitigation</strong><br>Yokogawa strongly recommends that all users establish and maintain a comprehensive security program, not just for addressing the vulnerability identified in this YSAR. Security program components include patch updates, antivirus software, backup and recovery solutions, zoning, hardening, whitelisting, firewalls, and other related measures. Yokogawa can assist organizations in setting up and continuously maintaining a security program. As a starting point for developing the most effective risk mitigation plan, Yokogawa offers security risk assessment services.</p>
<p><strong>Mitigation</strong><br>For questions related to this report, please contact Yokogawa https://contact.yokogawa.com/cs/gw?c-id=000498.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/497.html">CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66600</a></h3>
<div class="csaf-accordion-content">
<p>This product lacks HSTS (HTTP Strict Transport Security) configuration. When an attacker performs a Man in the middle (MITM) attack, communications with the web server could be sniffed.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66600">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa FAST/TOOLS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa FAST/TOOLS: &gt;=R9.01|&lt;=R10.04</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users update to revision R10.04 and apply patch software (CS_e12787). After the patch is applied, users should apply R10.04 SP3.</p>
<p><strong>Mitigation</strong><br>Yokogawa strongly recommends that all users establish and maintain a comprehensive security program, not just for addressing the vulnerability identified in this YSAR. Security program components include patch updates, antivirus software, backup and recovery solutions, zoning, hardening, whitelisting, firewalls, and other related measures. Yokogawa can assist organizations in setting up and continuously maintaining a security program. As a starting point for developing the most effective risk mitigation plan, Yokogawa offers security risk assessment services.</p>
<p><strong>Mitigation</strong><br>For questions related to this report, please contact Yokogawa https://contact.yokogawa.com/cs/gw?c-id=000498.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/358.html">CWE-358 Improperly Implemented Security Check for Standard</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.2</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66601</a></h3>
<div class="csaf-accordion-content">
<p>This product does not specify MIME types. When an attacker performs a content sniffing attack, malicious scripts could be executed.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66601">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa FAST/TOOLS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa FAST/TOOLS: &gt;=R9.01|&lt;=R10.04</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users update to revision R10.04 and apply patch software (CS_e12787). After the patch is applied, users should apply R10.04 SP3.</p>
<p><strong>Mitigation</strong><br>Yokogawa strongly recommends that all users establish and maintain a comprehensive security program, not just for addressing the vulnerability identified in this YSAR. Security program components include patch updates, antivirus software, backup and recovery solutions, zoning, hardening, whitelisting, firewalls, and other related measures. Yokogawa can assist organizations in setting up and continuously maintaining a security program. As a starting point for developing the most effective risk mitigation plan, Yokogawa offers security risk assessment services.</p>
<p><strong>Mitigation</strong><br>For questions related to this report, please contact Yokogawa https://contact.yokogawa.com/cs/gw?c-id=000498.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/358.html">CWE-358 Improperly Implemented Security Check for Standard</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66602</a></h3>
<div class="csaf-accordion-content">
<p>The web server accepts access by IP address. When a worm that randomly searches for IP addresses intrudes into the network, it could potentially be attacked by the worm.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66602">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa FAST/TOOLS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa FAST/TOOLS: &gt;=R9.01|&lt;=R10.04</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users update to revision R10.04 and apply patch software (CS_e12787). After the patch is applied, users should apply R10.04 SP3.</p>
<p><strong>Mitigation</strong><br>Yokogawa strongly recommends that all users establish and maintain a comprehensive security program, not just for addressing the vulnerability identified in this YSAR. Security program components include patch updates, antivirus software, backup and recovery solutions, zoning, hardening, whitelisting, firewalls, and other related measures. Yokogawa can assist organizations in setting up and continuously maintaining a security program. As a starting point for developing the most effective risk mitigation plan, Yokogawa offers security risk assessment services.</p>
<p><strong>Mitigation</strong><br>For questions related to this report, please contact Yokogawa https://contact.yokogawa.com/cs/gw?c-id=000498.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/291.html">CWE-291 Reliance on IP Address for Authentication</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66603</a></h3>
<div class="csaf-accordion-content">
<p>The web server accepts the OPTIONS method. An attacker could potentially use this information to carry out other attacks.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66603">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa FAST/TOOLS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa FAST/TOOLS: &gt;=R9.01|&lt;=R10.04</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users update to revision R10.04 and apply patch software (CS_e12787). After the patch is applied, users should apply R10.04 SP3.</p>
<p><strong>Mitigation</strong><br>Yokogawa strongly recommends that all users establish and maintain a comprehensive security program, not just for addressing the vulnerability identified in this YSAR. Security program components include patch updates, antivirus software, backup and recovery solutions, zoning, hardening, whitelisting, firewalls, and other related measures. Yokogawa can assist organizations in setting up and continuously maintaining a security program. As a starting point for developing the most effective risk mitigation plan, Yokogawa offers security risk assessment services.</p>
<p><strong>Mitigation</strong><br>For questions related to this report, please contact Yokogawa https://contact.yokogawa.com/cs/gw?c-id=000498.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/358.html">CWE-358 Improperly Implemented Security Check for Standard</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.1</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66604</a></h3>
<div class="csaf-accordion-content">
<p>The library version could be displayed on the web page. This information could be exploited by an attacker for other attacks.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66604">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa FAST/TOOLS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa FAST/TOOLS: &gt;=R9.01|&lt;=R10.04</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users update to revision R10.04 and apply patch software (CS_e12787). After the patch is applied, users should apply R10.04 SP3.</p>
<p><strong>Mitigation</strong><br>Yokogawa strongly recommends that all users establish and maintain a comprehensive security program, not just for addressing the vulnerability identified in this YSAR. Security program components include patch updates, antivirus software, backup and recovery solutions, zoning, hardening, whitelisting, firewalls, and other related measures. Yokogawa can assist organizations in setting up and continuously maintaining a security program. As a starting point for developing the most effective risk mitigation plan, Yokogawa offers security risk assessment services.</p>
<p><strong>Mitigation</strong><br>For questions related to this report, please contact Yokogawa https://contact.yokogawa.com/cs/gw?c-id=000498.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/319.html">CWE-319 Cleartext Transmission of Sensitive Information</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.1</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66605</a></h3>
<div class="csaf-accordion-content">
<p>Since there are input fields on this web page with the autocomplete attribute enabled, the input content could be saved in the browser the user is using.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66605">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa FAST/TOOLS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa FAST/TOOLS: &gt;=R9.01|&lt;=R10.04</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users update to revision R10.04 and apply patch software (CS_e12787). After the patch is applied, users should apply R10.04 SP3.</p>
<p><strong>Mitigation</strong><br>Yokogawa strongly recommends that all users establish and maintain a comprehensive security program, not just for addressing the vulnerability identified in this YSAR. Security program components include patch updates, antivirus software, backup and recovery solutions, zoning, hardening, whitelisting, firewalls, and other related measures. Yokogawa can assist organizations in setting up and continuously maintaining a security program. As a starting point for developing the most effective risk mitigation plan, Yokogawa offers security risk assessment services.</p>
<p><strong>Mitigation</strong><br>For questions related to this report, please contact Yokogawa https://contact.yokogawa.com/cs/gw?c-id=000498.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/359.html">CWE-359 Exposure of Private Personal Information to an Unauthorized Actor</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.1</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66606</a></h3>
<div class="csaf-accordion-content">
<p>This product does not properly encode URLs. An attacker could tamper with web pages or execute malicious scripts.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66606">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa FAST/TOOLS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa FAST/TOOLS: &gt;=R9.01|&lt;=R10.04</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users update to revision R10.04 and apply patch software (CS_e12787). After the patch is applied, users should apply R10.04 SP3.</p>
<p><strong>Mitigation</strong><br>Yokogawa strongly recommends that all users establish and maintain a comprehensive security program, not just for addressing the vulnerability identified in this YSAR. Security program components include patch updates, antivirus software, backup and recovery solutions, zoning, hardening, whitelisting, firewalls, and other related measures. Yokogawa can assist organizations in setting up and continuously maintaining a security program. As a starting point for developing the most effective risk mitigation plan, Yokogawa offers security risk assessment services.</p>
<p><strong>Mitigation</strong><br>For questions related to this report, please contact Yokogawa https://contact.yokogawa.com/cs/gw?c-id=000498.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/86.html">CWE-86 Improper Neutralization of Invalid Characters in Identifiers in Web Pages</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.4</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66607</a></h3>
<div class="csaf-accordion-content">
<p>The response header contains an insecure setting. Users could be redirected to malicious sites by an attacker.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66607">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa FAST/TOOLS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa FAST/TOOLS: &gt;=R9.01|&lt;=R10.04</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users update to revision R10.04 and apply patch software (CS_e12787). After the patch is applied, users should apply R10.04 SP3.</p>
<p><strong>Mitigation</strong><br>Yokogawa strongly recommends that all users establish and maintain a comprehensive security program, not just for addressing the vulnerability identified in this YSAR. Security program components include patch updates, antivirus software, backup and recovery solutions, zoning, hardening, whitelisting, firewalls, and other related measures. Yokogawa can assist organizations in setting up and continuously maintaining a security program. As a starting point for developing the most effective risk mitigation plan, Yokogawa offers security risk assessment services.</p>
<p><strong>Mitigation</strong><br>For questions related to this report, please contact Yokogawa https://contact.yokogawa.com/cs/gw?c-id=000498.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/358.html">CWE-358 Improperly Implemented Security Check for Standard</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.7</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-66608</a></h3>
<div class="csaf-accordion-content">
<p>This product fails to adequately validate URLs. An attacker could send maliciously crafted requests to gain unauthorized access to files on the web server.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66608">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Yokogawa FAST/TOOLS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Yokogawa</div>
<div class="ics-version"><strong>Product Version:</strong><br>Yokogawa FAST/TOOLS: &gt;=R9.01|&lt;=R10.04</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Yokogawa recommends users update to revision R10.04 and apply patch software (CS_e12787). After the patch is applied, users should apply R10.04 SP3.</p>
<p><strong>Mitigation</strong><br>Yokogawa strongly recommends that all users establish and maintain a comprehensive security program, not just for addressing the vulnerability identified in this YSAR. Security program components include patch updates, antivirus software, backup and recovery solutions, zoning, hardening, whitelisting, firewalls, and other related measures. Yokogawa can assist organizations in setting up and continuously maintaining a security program. As a starting point for developing the most effective risk mitigation plan, Yokogawa offers security risk assessment services.</p>
<p><strong>Mitigation</strong><br>For questions related to this report, please contact Yokogawa https://contact.yokogawa.com/cs/gw?c-id=000498.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/29.html">CWE-29 Path Traversal: '\..\filename'</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Yokogawa reported these vulnerabilities to CISA</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>
<p>Do not click web links or open attachments in unsolicited email messages.</p>
<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>
<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>
<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-02-10</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-02-10</td>
<td>1</td>
<td>Initial Republication of YSAR-26-0001-E</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa FAST/TOOLS]]></title>
<description><![CDATA[View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to redirected users to malicious sites, decrypt communications, perform a man-in-the-middle (MITM) attack, execute malicious scripts, steal files, and perform other various attacks. The following versions o...]]></description>
<link>https://tsecurity.de/de/3279939/it-security-nachrichten/yokogawa-fasttools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3279939/it-security-nachrichten/yokogawa-fasttools/</guid>
<pubDate>Tue, 10 Feb 2026 18:37:34 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to redirected users to malicious sites, decrypt communications, perform a man-in-the-middle (MITM) attack, execute malicious scripts, steal files, and perform other various attacks. The following versions of Yokogawa…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/yokogawa-fast-tools/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/yokogawa-fast-tools/">Yokogawa FAST/TOOLS</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-66599 | Yokogawa Electric FAST TOOLS up to R10.04 exposure of sensitive system information to an unauthorized control sphere (CNNVD-202602-1392)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Yokogawa Electric FAST TOOLS up to R10.04. This affects an unknown function. The manipulation leads to exposure of sensitive system information to an unauthorized control sphere.

This vulnerability is uniquely identified as CVE-2025-6659...]]></description>
<link>https://tsecurity.de/de/3279829/sicherheitsluecken/cve-2025-66599-yokogawa-electric-fast-tools-up-to-r1004-exposure-of-sensitive-system-information-to-an-unauthorized-control-sphere-cnnvd-202602-1392/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3279829/sicherheitsluecken/cve-2025-66599-yokogawa-electric-fast-tools-up-to-r1004-exposure-of-sensitive-system-information-to-an-unauthorized-control-sphere-cnnvd-202602-1392/</guid>
<pubDate>Tue, 10 Feb 2026 17:38:15 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/?kb.risk">problematic</a> has been reported in <a href="https://vuldb.com/?product.yokogawa_electric:fast_tools">Yokogawa Electric FAST TOOLS up to R10.04</a>. This affects an unknown function. The manipulation leads to exposure of sensitive system information to an unauthorized control sphere.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.344958">CVE-2025-66599</a>. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2014-0781 | Yokogawa CENTUM CS 3000 up to R3.07 BKCLogSvr.exe memory corruption (ID 42426 / XFDB-91783)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Yokogawa CENTUM CS 3000 up to R3.07. The affected element is an unknown function of the file BKCLogSvr.exe. Executing manipulation can lead to memory corruption.

This vulnerability is tracked as CVE-2014-0781. The attack can be launched remot...]]></description>
<link>https://tsecurity.de/de/3004771/sicherheitsluecken/cve-2014-0781-yokogawa-centum-cs-3000-up-to-r307-bkclogsvrexe-memory-corruption-id-42426-xfdb-91783/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3004771/sicherheitsluecken/cve-2014-0781-yokogawa-centum-cs-3000-up-to-r307-bkclogsvrexe-memory-corruption-id-42426-xfdb-91783/</guid>
<pubDate>Thu, 25 Sep 2025 20:52:36 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/?kb.risk">critical</a> has been found in <a href="https://vuldb.com/?product.yokogawa:centum_cs_3000">Yokogawa CENTUM CS 3000 up to R3.07</a>. The affected element is an unknown function of the file <em>BKCLogSvr.exe</em>. Executing manipulation can lead to memory corruption.

This vulnerability is tracked as <a href="https://vuldb.com/?source_cve.66623">CVE-2014-0781</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2014-0782 | Yokogawa Centum Vp Entry Class Software up to 5.03.00 Flow BKESimmgr.exe memory corruption (EDB-33331 / ID 42426)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Yokogawa Centum Vp Entry Class Software up to 5.03.00. This affects an unknown part of the file BKESimmgr.exe of the component Flow. The manipulation leads to memory corruption.

This vulnerability is uniquely identified as CVE-2014-078...]]></description>
<link>https://tsecurity.de/de/2943330/sicherheitsluecken/cve-2014-0782-yokogawa-centum-vp-entry-class-software-up-to-50300-flow-bkesimmgrexe-memory-corruption-edb-33331-id-42426/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2943330/sicherheitsluecken/cve-2014-0782-yokogawa-centum-vp-entry-class-software-up-to-50300-flow-bkesimmgrexe-memory-corruption-edb-33331-id-42426/</guid>
<pubDate>Sat, 16 Aug 2025 20:52:25 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/?kb.risk">critical</a> has been identified in <a href="https://vuldb.com/?product.yokogawa:centum_vp_entry_class_software">Yokogawa Centum Vp Entry Class Software up to 5.03.00</a>. This affects an unknown part of the file <em>BKESimmgr.exe</em> of the component <em>Flow</em>. The manipulation leads to memory corruption.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.69705">CVE-2014-0782</a>. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2014-0783 | Yokogawa CENTUM CS 3000 up to R3.07 BKHOdeq.exe memory corruption (EDB-32209 / ID 42426)]]></title>
<description><![CDATA[A vulnerability was found in Yokogawa CENTUM CS 3000 up to R3.07. It has been classified as critical. Affected is an unknown function of the file BKHOdeq.exe. The manipulation leads to memory corruption.

This vulnerability is traded as CVE-2014-0783. It is possible to launch the attack remotely....]]></description>
<link>https://tsecurity.de/de/2938032/sicherheitsluecken/cve-2014-0783-yokogawa-centum-cs-3000-up-to-r307-bkhodeqexe-memory-corruption-edb-32209-id-42426/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2938032/sicherheitsluecken/cve-2014-0783-yokogawa-centum-cs-3000-up-to-r307-bkhodeqexe-memory-corruption-edb-32209-id-42426/</guid>
<pubDate>Wed, 13 Aug 2025 18:06:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.yokogawa:centum_cs_3000">Yokogawa CENTUM CS 3000 up to R3.07</a>. It has been classified as <a href="https://vuldb.com/?kb.risk">critical</a>. Affected is an unknown function of the file <em>BKHOdeq.exe</em>. The manipulation leads to memory corruption.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.66624">CVE-2014-0783</a>. It is possible to launch the attack remotely. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2014-0784 | Yokogawa CENTUM CS 3000 up to R3.07 BKBCopyD.exe memory corruption (EDB-32210 / ID 42426)]]></title>
<description><![CDATA[A vulnerability was found in Yokogawa CENTUM CS 3000 up to R3.07. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file BKBCopyD.exe. The manipulation leads to memory corruption.

This vulnerability is known as CVE-2014-0784. The attack can be la...]]></description>
<link>https://tsecurity.de/de/2938031/sicherheitsluecken/cve-2014-0784-yokogawa-centum-cs-3000-up-to-r307-bkbcopydexe-memory-corruption-edb-32210-id-42426/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2938031/sicherheitsluecken/cve-2014-0784-yokogawa-centum-cs-3000-up-to-r307-bkbcopydexe-memory-corruption-edb-32210-id-42426/</guid>
<pubDate>Wed, 13 Aug 2025 18:06:55 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.yokogawa:centum_cs_3000">Yokogawa CENTUM CS 3000 up to R3.07</a>. It has been declared as <a href="https://vuldb.com/?kb.risk">critical</a>. Affected by this vulnerability is an unknown functionality of the file <em>BKBCopyD.exe</em>. The manipulation leads to memory corruption.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.66625">CVE-2014-0784</a>. The attack can be launched remotely. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[What a mature OT security program looks like in practice]]></title>
<description><![CDATA[In this Help Net Security interview, Cindy Segond von Banchet CC, Cybersecurity Lead at Yokogawa Europe, shares her insights on what defines a sustainable OT security program. She outlines the key differences between short-term fixes and long-term resilience, and discusses how organizations can e...]]></description>
<link>https://tsecurity.de/de/2891583/it-security-nachrichten/what-a-mature-ot-security-program-looks-like-in-practice/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2891583/it-security-nachrichten/what-a-mature-ot-security-program-looks-like-in-practice/</guid>
<pubDate>Thu, 17 Jul 2025 08:04:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this Help Net Security interview, Cindy Segond von Banchet CC, Cybersecurity Lead at Yokogawa Europe, shares her insights on what defines a sustainable OT security program. She outlines the key differences between short-term fixes and long-term resilience, and discusses how organizations can embed OT security within broader risk frameworks. From addressing legacy system vulnerabilities to integrating OT into existing SOC operations, she covers topics such as visibility, training, and alignment with global standards like … <a href="https://www.helpnetsecurity.com/2025/07/17/cindy-segond-von-banchet-cc-yokogawa-how-to-build-ot-security-program/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2025/07/17/cindy-segond-von-banchet-cc-yokogawa-how-to-build-ot-security-program/">What a mature OT security program looks like in practice</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Releases Six Industrial Control Systems Advisories]]></title>
<description><![CDATA[CISA released six Industrial Control Systems (ICS) advisories on April 17, 2025. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.

ICSA-25-107-01 Schneider Electric Trio Q Licensed Data Radio
ICSA-25-107-02 Schneider Electri...]]></description>
<link>https://tsecurity.de/de/2730662/it-security-nachrichten/cisa-releases-six-industrial-control-systems-advisories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2730662/it-security-nachrichten/cisa-releases-six-industrial-control-systems-advisories/</guid>
<pubDate>Thu, 17 Apr 2025 19:34:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>CISA released six Industrial Control Systems (ICS) advisories on April 17, 2025. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.</p>
<ul>
<li>ICSA-25-107-01 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-25-107-01">Schneider Electric Trio Q Licensed Data Radio</a></li>
<li>ICSA-25-107-02 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-25-107-02">Schneider Electric Sage Series</a></li>
<li>ICSA-25-107-03 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-25-107-03">Schneider Electric ConneXium Network Manager</a></li>
<li>ICSA-25-107-04 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-25-107-04">Yokogawa Recorder Products</a></li>
<li>ICSA-24-326-04 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-326-04">Schneider Electric Modicon M340, MC80, and Momentum Unity M1E (Update A)</a></li>
<li>ICSA-25-058-01 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-25-058-01">Schneider Electric Communication Modules for Modicon M580 and Quantum Controllers (Update A)</a><br> </li>
</ul>
<p>CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa Recorder Products]]></title>
<description><![CDATA[View CSAF
1. EXECUTIVE SUMMARY

CVSS v4 9.3
ATTENTION: Exploitable remotely/low attack complexity
Vendor: Yokogawa
Equipment: GX10, GX20, GP10, GP20, GM Data Acquisition System, DX1000, DX2000, DX1000N, FX1000, μR10000, μR20000, MW100, DX1000T, DX2000T, CX1000, CX2000
Vulnerability: Missing Authe...]]></description>
<link>https://tsecurity.de/de/2730661/it-security-nachrichten/yokogawa-recorder-products/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2730661/it-security-nachrichten/yokogawa-recorder-products/</guid>
<pubDate>Thu, 17 Apr 2025 19:34:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p>
<h2>1. EXECUTIVE SUMMARY</h2>
<ul>
<li><strong>CVSS v4 9.3</strong></li>
<li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li>
<li><strong>Vendor</strong>: Yokogawa</li>
<li><strong>Equipment</strong>: GX10, GX20, GP10, GP20, GM Data Acquisition System, DX1000, DX2000, DX1000N, FX1000, μR10000, μR20000, MW100, DX1000T, DX2000T, CX1000, CX2000</li>
<li><strong>Vulnerability</strong>: Missing Authentication for Critical Function</li>
</ul>
<h2>2. RISK EVALUATION</h2>
<p>Successful exploitation of this vulnerability could allow an attacker to manipulate information on the affected products.</p>
<h2>3. TECHNICAL DETAILS</h2>
<h3>3.1 AFFECTED PRODUCTS</h3>
<p>The following versions of Yokogawa recorder products are affected:</p>
<ul>
<li>GX10 / GX20 / GP10 / GP20 Paperless Recorders: Versions R5.04.01 and earlier</li>
<li>GM Data Acquisition System: Versions R5.05.01 and earlier</li>
<li>DX1000 / DX2000 / DX1000N Paperless Recorders: Versions R4.21 and earlier</li>
<li>FX1000 Paperless Recorders: Versions R1.31 and earlier</li>
<li>μR10000 / μR20000 Chart Recorders: Versions R1.51 and earlier</li>
<li>MW100 Data Acquisition Units: All versions</li>
<li>DX1000T / DX2000T Paperless Recorders: All versions</li>
<li>CX1000 / CX2000 Paperless Recorders: All versions</li>
</ul>
<h3>3.2 VULNERABILITY OVERVIEW</h3>
<h4><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank"><strong>MISSING AUTHENTICATION FOR CRITICAL FUNCTION CWE-306</strong></a></h4>
<p>Authentication is disabled by default on the affected products. When connected to a network with default settings, this could allow anyone to access all functions related to settings and operations. As a result, an attacker can illegally manipulate and configure important data such as measured values and settings.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-1863" target="_blank">CVE-2025-1863</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2025-1863" target="_blank">CVE-2025-1863</a>. A base score of 9.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p>
<h3>3.3 BACKGROUND</h3>
<ul>
<li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing, Energy, Food and Agriculture</li>
<li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li>
<li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Japan</li>
</ul>
<h3>3.4 RESEARCHER</h3>
<p>Souvik Kandar of MicroSec (microsec.io) reported this vulnerability to CISA.</p>
<h2>4. MITIGATIONS</h2>
<p>Yokogawa has provided the following countermeasures for this vulnerability:</p>
<ul>
<li>Yokogawa urges users to enable the authentication function when connecting the affected products to the network (login function).</li>
<li>Be sure to change the password from the default setting after enabling the authentication function.</li>
</ul>
<p>Yokogawa strongly recommends all users to establish and maintain a full security program. Security program components are patch updates, anti-virus, backup and recovery, zoning, hardening, whitelisting, firewall, etc. Yokogawa can assist in setting up and running the security program continuously. For considering the most effective risk mitigation plan, as a starting point, Yokogawa can perform a security risk assessment.</p>
<p>For more information, <a href="https://contact.yokogawa.com/cs/gw?c-id=000498" target="_blank">contact Yokogawa</a>.</p>
<p>For more information and details on implementing these mitigations, users should see the <a href="https://www.yokogawa.com/library/resources/white-papers/yokogawa-security-advisory-report-list/" target="_blank">Yokogawa advisory.</a></p>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:</p>
<ul>
<li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li>
<li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li>
<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li>
</ul>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>
<h2>5. UPDATE HISTORY</h2>
<ul>
<li>April 17, 2025: Initial Publication</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-23847 | Yokogawa Rental & Lease Unifier/Unifier Cast permission (ID 20240527)]]></title>
<description><![CDATA[A vulnerability was found in Yokogawa Rental & Lease Unifier and Unifier Cast. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to permission issues.

The identification of this vulnerability is CVE-2024-23847. The attack needs to be done within th...]]></description>
<link>https://tsecurity.de/de/2711579/sicherheitsluecken/cve-2024-23847-yokogawa-rental-lease-unifierunifier-cast-permission-id-20240527/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2711579/sicherheitsluecken/cve-2024-23847-yokogawa-rental-lease-unifierunifier-cast-permission-id-20240527/</guid>
<pubDate>Tue, 08 Apr 2025 10:37:31 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.yokogawa_rental__lease:unifier">Yokogawa Rental &amp; Lease Unifier and Unifier Cast</a>. It has been rated as <a href="https://vuldb.com/?kb.risk">critical</a>. This issue affects some unknown processing. The manipulation leads to permission issues.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.266759">CVE-2024-23847</a>. The attack needs to be done within the local network. There is no exploit available.

It is recommended to apply a patch to fix this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-4105 | Yokogawa Electric FAST TOOLS/CI Server Request cross site scripting]]></title>
<description><![CDATA[A vulnerability was found in Yokogawa Electric FAST TOOLS and CI Server and classified as problematic. This issue affects some unknown processing of the component Request Handler. The manipulation leads to cross site scripting.

The identification of this vulnerability is CVE-2024-4105. The attac...]]></description>
<link>https://tsecurity.de/de/2680549/sicherheitsluecken/cve-2024-4105-yokogawa-electric-fast-toolsci-server-request-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2680549/sicherheitsluecken/cve-2024-4105-yokogawa-electric-fast-toolsci-server-request-cross-site-scripting/</guid>
<pubDate>Sat, 22 Mar 2025 07:43:35 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.yokogawa_electric:fast_tools">Yokogawa Electric FAST TOOLS and CI Server</a> and classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. This issue affects some unknown processing of the component <em>Request Handler</em>. The manipulation leads to cross site scripting.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.269735">CVE-2024-4105</a>. The attack may be initiated remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Dragos und Yokogawa besiegeln globale Partnerschaft - atpinfo.de]]></title>
<description><![CDATA[Der Cybersecurity-Spezialist Dragos und Yokogawa haben ihre globale Partnerschaft bekanntgegeben. Das Ziel der Kooperation: die Sicherung der ...]]></description>
<link>https://tsecurity.de/de/2599421/it-security-nachrichten/dragos-und-yokogawa-besiegeln-globale-partnerschaft-atpinfode/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2599421/it-security-nachrichten/dragos-und-yokogawa-besiegeln-globale-partnerschaft-atpinfode/</guid>
<pubDate>Fri, 07 Feb 2025 11:04:03 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Cybersecurity-Spezialist Dragos und Yokogawa haben ihre globale Partnerschaft bekanntgegeben. Das Ziel der Kooperation: die Sicherung der ...]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-8110 | Yokogawa Electric Dual-redundant Platform for Computer PC2CKM up to R2.03.00 UDP Broadcast return value]]></title>
<description><![CDATA[A vulnerability was found in Yokogawa Electric Dual-redundant Platform for Computer PC2CKM up to R2.03.00. It has been classified as critical. Affected is an unknown function of the component UDP Broadcast Handler. The manipulation leads to unchecked return value.

This vulnerability is traded as...]]></description>
<link>https://tsecurity.de/de/2344963/sicherheitsluecken/cve-2024-8110-yokogawa-electric-dual-redundant-platform-for-computer-pc2ckm-up-to-r20300-udp-broadcast-return-value/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2344963/sicherheitsluecken/cve-2024-8110-yokogawa-electric-dual-redundant-platform-for-computer-pc2ckm-up-to-r20300-udp-broadcast-return-value/</guid>
<pubDate>Sat, 21 Sep 2024 05:37:43 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.yokogawa_electric:dual-redundant_platform_for_computer_pc2ckm">Yokogawa Electric Dual-redundant Platform for Computer PC2CKM up to R2.03.00</a>. It has been classified as <a href="https://vuldb.com/?kb.risk">critical</a>. Affected is an unknown function of the component <em>UDP Broadcast Handler</em>. The manipulation leads to unchecked return value.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.277602">CVE-2024-8110</a>. It is possible to launch the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa Dual-redundant Platform for Computer (PC2CKM)]]></title>
<description><![CDATA[View CSAF
1. EXECUTIVE SUMMARY

CVSS v3 7.5
ATTENTION: Exploitable remotely/low attack complexity
Vendor: Yokogawa
Equipment: Dual-redundant Platform for Computer (PC2CKM)
Vulnerability: Unchecked Return Value

2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attack...]]></description>
<link>https://tsecurity.de/de/2337815/it-security-nachrichten/yokogawa-dual-redundant-platform-for-computer-pc2ckm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2337815/it-security-nachrichten/yokogawa-dual-redundant-platform-for-computer-pc2ckm/</guid>
<pubDate>Tue, 17 Sep 2024 17:05:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p>
<h2>1. EXECUTIVE SUMMARY</h2>
<ul>
<li><strong>CVSS v3 7.5</strong></li>
<li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li>
<li><strong>Vendor</strong>: Yokogawa</li>
<li><strong>Equipment</strong>: Dual-redundant Platform for Computer (PC2CKM)</li>
<li><strong>Vulnerability</strong>: Unchecked Return Value</li>
</ul>
<h2>2. RISK EVALUATION</h2>
<p>Successful exploitation of this vulnerability could allow an attacker to perform a denial-of-service.</p>
<h2>3. TECHNICAL DETAILS</h2>
<h3>3.1 AFFECTED PRODUCTS</h3>
<p>The following versions of Yokogawa PC2CKM, a dual-redundant platform computer, are affected:</p>
<ul>
<li>Dual-redundant Platform for Computer (PC2CKM): R1.01.00 to R2.03.00</li>
</ul>
<h3>3.2 Vulnerability Overview</h3>
<h4><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/252.html" target="_blank"><strong>UNCHECKED RETURN VALUE CWE-252</strong></a></h4>
<p>If a computer on which the affected product is installed receives a large number of UDP broadcast packets in a short period, occasionally that computer may restart. If both the active and standby computers are restarted at the same time, the functionality on that computer may be temporarily unavailable.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-8110" target="_blank">CVE-2024-8110</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<h3>3.3 BACKGROUND</h3>
<ul>
<li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing, Energy, Food and Agriculture</li>
<li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li>
<li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Japan</li>
</ul>
<h3>3.4 RESEARCHER</h3>
<p>Yokogawa reported this vulnerability to JPCERT.</p>
<h2>4. MITIGATIONS</h2>
<p>Yokogawa recommends users update to the following version:</p>
<ul>
<li>Dual-redundant Platform for Computer (PC2CKM): Update to R2.03.10</li>
</ul>
<p>For more information, <a href="https://contact.yokogawa.com/cs/gw?c-id=000498" target="_blank">contact Yokogawa</a>.</p>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:</p>
<ul>
<li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li>
<li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li>
<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li>
</ul>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>
<h2>5. UPDATE HISTORY</h2>
<ul>
<li>September 17, 2024: Initial Publication</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Releases Three Industrial Control Systems Advisories]]></title>
<description><![CDATA[CISA released three Industrial Control Systems (ICS) advisories on September 17, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.

ICSA-24-261-01 Siemens SIMATIC S7-200 SMART Devices
ICSA-24-261-02 Millbeck Communicati...]]></description>
<link>https://tsecurity.de/de/2337811/it-security-nachrichten/cisa-releases-three-industrial-control-systems-advisories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2337811/it-security-nachrichten/cisa-releases-three-industrial-control-systems-advisories/</guid>
<pubDate>Tue, 17 Sep 2024 17:05:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>CISA released three Industrial Control Systems (ICS) advisories on September 17, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.</p>
<ul type="disc">
<li>ICSA-24-261-01 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-261-01">Siemens SIMATIC S7-200 SMART Devices</a></li>
<li>ICSA-24-261-02 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-261-02">Millbeck Communications Proroute H685t-w</a></li>
<li>ICSA-24-261-03 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-261-03">Yokogawa Dual-redundant Platform for Computer (PC2CKM)</a></li>
</ul>
<p>CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa BKBCopyD.exe Client]]></title>
<description><![CDATA[This Metasploit module allows an unauthenticated user to interact with the Yokogawa CENTUM CS3000 BKBCopyD.exe service through the PMODE, RETR and STOR operations.]]></description>
<link>https://tsecurity.de/de/2309404/it-security-tools/yokogawa-bkbcopydexe-client/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2309404/it-security-tools/yokogawa-bkbcopydexe-client/</guid>
<pubDate>Sat, 31 Aug 2024 23:19:00 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This Metasploit module allows an unauthenticated user to interact with the Yokogawa CENTUM CS3000 BKBCopyD.exe service through the PMODE, RETR and STOR operations.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-36246 | Yokogawa Rental & Lease Unifier/Unifier Cast authorization (ID 20240527)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in Yokogawa Rental & Lease Unifier and Unifier Cast. Affected is an unknown function. The manipulation leads to missing authorization.

This vulnerability is traded as CVE-2024-36246. The attack needs to be initiated within the local network. ...]]></description>
<link>https://tsecurity.de/de/2280658/sicherheitsluecken/cve-2024-36246-yokogawa-rental-lease-unifierunifier-cast-authorization-id-20240527/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2280658/sicherheitsluecken/cve-2024-36246-yokogawa-rental-lease-unifierunifier-cast-authorization-id-20240527/</guid>
<pubDate>Thu, 15 Aug 2024 22:05:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> has been found in <a href="https://vuldb.com/?product.yokogawa_rental__lease:unifier">Yokogawa Rental &amp; Lease Unifier and Unifier Cast</a>. Affected is an unknown function. The manipulation leads to missing authorization.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.266760">CVE-2024-36246</a>. The attack needs to be initiated within the local network. There is no exploit available.

It is recommended to apply a patch to fix this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2014-3888 | Yokogawa Centum Vp Entry Class Software up to 5.03.00 Flow BKFSim_vhfd.exe FCS/Test memory corruption (ID 127382 / EDB-34009)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Yokogawa Centum Vp Entry Class Software up to 5.03.00. Affected is the function FCS/Test of the file BKFSim_vhfd.exe of the component Flow. The manipulation leads to memory corruption.

This vulnerability is traded as CVE-2014-3888. ...]]></description>
<link>https://tsecurity.de/de/2206267/sicherheitsluecken/cve-2014-3888-yokogawa-centum-vp-entry-class-software-up-to-50300-flow-bkfsimvhfdexe-fcstest-memory-corruption-id-127382-edb-34009/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2206267/sicherheitsluecken/cve-2014-3888-yokogawa-centum-vp-entry-class-software-up-to-50300-flow-bkfsimvhfdexe-fcstest-memory-corruption-id-127382-edb-34009/</guid>
<pubDate>Sun, 30 Jun 2024 15:08:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, was found in <a href="https://vuldb.com/?product.yokogawa:centum_vp_entry_class_software">Yokogawa Centum Vp Entry Class Software up to 5.03.00</a>. Affected is the function <code>FCS/Test</code> of the file <em>BKFSim_vhfd.exe</em> of the component <em>Flow</em>. The manipulation leads to memory corruption.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.70320">CVE-2014-3888</a>. It is possible to launch the attack remotely. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Releases Seven Industrial Control Systems Advisories]]></title>
<description><![CDATA[CISA released seven Industrial Control Systems (ICS) advisories on June 27, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.

ICSA-24-179-01 TELSAT marKoni FM Transmitter
ICSA-24-179-02 SDG Technologies PnPSCADA
ICSA-2...]]></description>
<link>https://tsecurity.de/de/2201951/it-security-nachrichten/cisa-releases-seven-industrial-control-systems-advisories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2201951/it-security-nachrichten/cisa-releases-seven-industrial-control-systems-advisories/</guid>
<pubDate>Thu, 27 Jun 2024 16:52:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>CISA released seven Industrial Control Systems (ICS) advisories on June 27, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.</p>
<ul type="disc">
<li>ICSA-24-179-01 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-179-01">TELSAT marKoni FM Transmitter</a></li>
<li>ICSA-24-179-02 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-179-02">SDG Technologies PnPSCADA</a></li>
<li>ICSA-24-179-03 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-179-03">Yokogawa FAST/TOOLS and CI Server</a></li>
<li>ICSA-24-179-04 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-179-04">Johnson Controls Illustra Essentials Gen 4</a></li>
<li>ICSA-24-179-05 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-179-05">Johnson Controls Illustra Essentials Gen 4</a></li>
<li>ICSA-24-179-06 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-179-06">Johnson Controls Illustra Essentials Gen 4</a></li>
<li>ICSA-24-179-07 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-179-07">Johnson Controls Illustra Essentials Gen 4</a></li>
</ul>
<p>CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa FAST/TOOLS and CI Server]]></title>
<description><![CDATA[View CSAF
1. EXECUTIVE SUMMARY

CVSS v4 6.9
ATTENTION: Exploitable remotely/low attack complexity
Vendor: Yokogawa
Equipment: FAST/TOOLS and CI Server
Vulnerabilities: Cross-site Scripting, Empty Password in Configuration File

2. RISK EVALUATION
Successful exploitation of these vulnerabilities c...]]></description>
<link>https://tsecurity.de/de/2201950/it-security-nachrichten/yokogawa-fasttools-and-ci-server/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2201950/it-security-nachrichten/yokogawa-fasttools-and-ci-server/</guid>
<pubDate>Thu, 27 Jun 2024 16:52:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p>
<h2>1. EXECUTIVE SUMMARY</h2>
<ul>
<li><strong>CVSS v4 6.9</strong></li>
<li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li>
<li><strong>Vendor</strong>: Yokogawa</li>
<li><strong>Equipment</strong>: FAST/TOOLS and CI Server</li>
<li><strong>Vulnerabilities</strong>: Cross-site Scripting, Empty Password in Configuration File</li>
</ul>
<h2>2. RISK EVALUATION</h2>
<p>Successful exploitation of these vulnerabilities could allow an attacker to launch a malicious script and take control of affected products.</p>
<h2>3. TECHNICAL DETAILS</h2>
<h3>3.1 AFFECTED PRODUCTS</h3>
<p>The following versions of Yokogawa FAST/TOOLS and CI Server, SCADA software environments, are affected:</p>
<ul>
<li>FAST/TOOLS RVSVRN Package: Versions R9.01 through R10.04</li>
<li>FAST/TOOLS UNSVRN Package: Versions R9.01 through R10.04</li>
<li>FAST/TOOLS HMIWEB Package: Versions R9.01 through R10.04</li>
<li>FAST/TOOLS FTEES Package: Versions R9.01 through R10.04</li>
<li>FAST/TOOLS HMIMOB Package: Versions R9.01 through R10.04</li>
<li>CI Server: Versions R1.01.00 through R1.03.00</li>
</ul>
<h3>3.2 Vulnerability Overview</h3>
<h4><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank"><strong>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-79</strong></a></h4>
<p>The affected product's WEB HMI server's function to process HTTP requests has a security flaw (reflected XSS) that allows the execution of malicious scripts. Therefore, if a client PC with inadequate security measures accesses a product URL containing a malicious request, the malicious script may be executed on the client PC.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-4105" target="_blank">CVE-2024-4105</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 5.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" target="_blank">AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N</a>).</p>
<p>A CVSS v4 score has also been calculated for <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-4105" target="_blank">CVE-2024-4105</a>. A base score of 6.9 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N" target="_blank">CVSS4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N</a>).</p>
<h4><strong>3.2.2 </strong><a href="https://cwe.mitre.org/data/definitions/258.html" target="_blank"><strong>Empty Password in Configuration File CWE-258</strong></a></h4>
<p>The affected products have built-in accounts with no passwords set. Therefore, if the product is operated without a password set by default, an attacker can break into the affected product.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-4106" target="_blank">CVE-2024-4106</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank">AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a>.</p>
<p>A CVSS v4 score has also been calculated for <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-4106" target="_blank">CVE-2024-4106</a>. A base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N" target="_blank">CVSS4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N</a>).</p>
<h3>3.3 BACKGROUND</h3>
<ul>
<li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing, Energy, Food and Agriculture</li>
<li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li>
<li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Japan</li>
</ul>
<h3>3.4 RESEARCHER</h3>
<p>Yokogawa reported these vulnerabilities to CISA.</p>
<h2>4. MITIGATIONS</h2>
<p>Yokogawa recommends customers using FAST/TOOLS to update to R10.04 and first apply patch software R10.04 SP3 and afterwards apply patch software I12560.</p>
<p>Yokogawa recommends customers using Collaborative Information Server (CI Server) to update to R1.03.00 and apply patch software R10.04 SP3.</p>
<p>For both platforms, if the password for the default account has not been changed, please change that password according to the documentation included with the patch software.</p>
<p>Yokogawa strongly recommends all customers to establish and maintain a full security program, not only for the vulnerability identified in this YSAR. Security program components are: Patch updates, Anti-virus, Backup and recovery, zoning, hardening, whitelisting, firewall, etc. Yokogawa can assist in setting up and running the security program continuously. For considering the most effective risk mitigation plan, as a starting point, Yokogawa can perform a security risk assessment.</p>
<p>For questions related to this report, please contact <a href="https://contact.yokogawa.com/cs/gw?c-id=000498" target="_blank">Yokogawa</a>.</p>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>
<ul>
<li>Do not click web links or open attachments in unsolicited email messages.</li>
<li>Refer to <a href="https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf" target="_blank">Recognizing and Avoiding Email Scams</a> for more information on avoiding email scams.</li>
<li>Refer to <a href="https://www.cisa.gov/uscert/ncas/tips/ST04-014" target="_blank">Avoiding Social Engineering and Phishing Attacks</a> for more information on social engineering attacks.</li>
</ul>
<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>
<h2>5. UPDATE HISTORY</h2>
<ul>
<li>June 27, 2024: Initial Publication</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa CENTUM]]></title>
<description><![CDATA[View CSAF
1. EXECUTIVE SUMMARY

CVSS v4 7.7
ATTENTION: Exploitable remotely/Low attack complexity
Vendor: Yokogawa
Equipment: CENTUM
Vulnerability: Uncontrolled Search Path Element

2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary progr...]]></description>
<link>https://tsecurity.de/de/2190650/it-security-nachrichten/yokogawa-centum/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2190650/it-security-nachrichten/yokogawa-centum/</guid>
<pubDate>Thu, 20 Jun 2024 16:19:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p>
<h2>1. EXECUTIVE SUMMARY</h2>
<ul>
<li><strong>CVSS v4 7.7</strong></li>
<li><strong>ATTENTION</strong>: Exploitable remotely/Low attack complexity</li>
<li><strong>Vendor</strong>: Yokogawa</li>
<li><strong>Equipment</strong>: CENTUM</li>
<li><strong>Vulnerability</strong>: Uncontrolled Search Path Element</li>
</ul>
<h2>2. RISK EVALUATION</h2>
<p>Successful exploitation of this vulnerability could allow an attacker to execute arbitrary programs.</p>
<h2>3. TECHNICAL DETAILS</h2>
<h3>3.1 AFFECTED PRODUCTS</h3>
<p>The following versions of Yokogawa CENTUM, a distributed control system (DCS), are affected:</p>
<ul>
<li>CENTUM CS 3000 (Including CENTUM CS 3000 Entry Class): Version R3.08.10 to R3.09.50</li>
<li>CENTUM VP (Including CENTUM VP Entry Class): Version R4.01.00 to R4.03.00</li>
<li>CENTUM VP (Including CENTUM VP Entry Class): Version R5.01.00 to R5.04.20</li>
<li>CENTUM VP (Including CENTUM VP Entry Class): Version R6.01.00 to R6.11.10</li>
</ul>
<h3>3.2 Vulnerability Overview</h3>
<h4><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank"><strong>Improper Access Control CWE-284</strong></a></h4>
<p>If an attacker is somehow able to intrude into a computer that installed affected product or access to a shared folder, by replacing the DLL file with a tampered one, it is possible to execute arbitrary programs with the authority of the SYSTEM account.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-5650" target="_blank">CVE-2024-5650</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 8.5 has been calculated; the CVSS vector string is (<a href="https://jvndb.jvn.jp/cvss/en/v3.html#CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank">AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</a>).</p>
<p>A CVSS v4 score has also been calculated for <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-5650" target="_blank">CVE-2024-5650</a>. A base score of 7.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p>
<h3>3.3 BACKGROUND</h3>
<ul>
<li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing, Energy, Food and Agriculture</li>
<li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li>
<li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Japan</li>
</ul>
<h3>3.4 RESEARCHER</h3>
<p>JPCERT/CC reported this vulnerability to CISA.</p>
<h2>4. MITIGATIONS</h2>
<p>Yokogawa recommends that customers update to CENTUM VP or CENTUM VP Entry Class R6.11.12 or later. CENTUM CS and earlier versions of Centum VP will not be patched because these products are no longer supported.</p>
<p>Yokogawa strongly recommends all customers to establish and maintain a full security program, not just for the vulnerability identified in this advisory. Security program components are: Patch updates, Anti-virus, Backup and recovery, zoning, hardening, whitelisting, firewall, etc. Yokogawa can assist in setting up and running a security program continuously. Yokogawa can perform a security risk assessment for users considering the most effective risk mitigation plan.</p>
<p>For questions related to this report, please contact <a href="https://contact.yokogawa.com/cs/gw?c-id=000498" target="_blank">Yokogawa</a>.</p>
<p>For more information and details on implementing these mitigations and downloading the latest patch, users should see <a href="https://web-material3.yokogawa.com/1/36044/files/YSAR-24-0002-E.pdf" target="_blank">Yokogawa advisory YSAR-24-0002.</a></p>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:</p>
<ul>
<li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li>
<li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li>
<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li>
</ul>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>
<h2>5. UPDATE HISTORY</h2>
<ul>
<li>June 20, 2024: Initial Publication</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Releases Three Industrial Control Systems Advisories]]></title>
<description><![CDATA[CISA released three Industrial Control Systems (ICS) advisories on June 20, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.

ICSA-24-172-01 Yokogawa CENTUM
ICSA-24-172-02 CAREL Boss-Mini
ICSA-24-172-03 Westermo L210-F...]]></description>
<link>https://tsecurity.de/de/2190649/it-security-nachrichten/cisa-releases-three-industrial-control-systems-advisories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2190649/it-security-nachrichten/cisa-releases-three-industrial-control-systems-advisories/</guid>
<pubDate>Thu, 20 Jun 2024 16:19:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="l-page-section l-page-section--rich-text">
<div class="l-constrain">
<div class="l-page-section__content">
<p>CISA released three Industrial Control Systems (ICS) advisories on June 20, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.</p>
<ul type="disc">
<li>ICSA-24-172-01 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-172-01">Yokogawa CENTUM</a></li>
<li>ICSA-24-172-02 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-172-02">CAREL Boss-Mini</a></li>
<li>ICSA-24-172-03 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-172-03">Westermo L210-F2G</a></li>
</ul>
<p>CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations.</p>
</div>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-5915 | Yokogawa STARDOM FCN-FJC up to R4.31 Packet resource consumption (icsa-23-334-02)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Yokogawa STARDOM FCN-FJC up to R4.31. Affected by this vulnerability is an unknown functionality of the component Packet Handler. The manipulation leads to resource consumption.

This vulnerability is known as CVE-2023-5915. The attack can be...]]></description>
<link>https://tsecurity.de/de/1965171/sicherheitsluecken/cve-2023-5915-yokogawa-stardom-fcn-fjc-up-to-r431-packet-resource-consumption-icsa-23-334-02/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1965171/sicherheitsluecken/cve-2023-5915-yokogawa-stardom-fcn-fjc-up-to-r431-packet-resource-consumption-icsa-23-334-02/</guid>
<pubDate>Thu, 21 Dec 2023 10:09:23 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">problematic</a> was found in <a href="https://vuldb.com/?product.yokogawa:stardom_fcn-fjc">Yokogawa STARDOM FCN-FJC up to R4.31</a>. Affected by this vulnerability is an unknown functionality of the component <em>Packet Handler</em>. The manipulation leads to resource consumption.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.246511">CVE-2023-5915</a>. The attack can be launched remotely. There is no exploit available.

It is recommended to apply restrictive firewalling.]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa STARDOM]]></title>
<description><![CDATA[View CSAF
1. EXECUTIVE SUMMARY
CVSS v3 5.3
ATTENTION: Exploitable remotely/low attack complexity
Vendor: Yokogawa
Equipment: STARDOM FCN/FCJ
Vulnerability: Uncontrolled Resource Consumption
2. RISK EVALUATION
Successful exploitation of this vulnerability could allow a remote attacker to cause a d...]]></description>
<link>https://tsecurity.de/de/1946297/it-security-nachrichten/yokogawa-stardom/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1946297/it-security-nachrichten/yokogawa-stardom/</guid>
<pubDate>Thu, 30 Nov 2023 17:06:03 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><strong><a href="https://github.com/cisagov/CSAF" target="_blank">View CSAF</a></strong></p>
<h2>1. EXECUTIVE SUMMARY</h2>
<ul><li><strong>CVSS v3 5.3</strong></li>
<li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li>
<li><strong>Vendor</strong>: Yokogawa</li>
<li><strong>Equipment</strong>: STARDOM FCN/FCJ</li>
<li><strong>Vulnerability</strong>: Uncontrolled Resource Consumption</li>
</ul><h2>2. RISK EVALUATION</h2>
<p>Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service condition to the FCN/FCJ controller by sending a specially crafted packet.</p>
<h2>3. TECHNICAL DETAILS</h2>
<h3>3.1 AFFECTED PRODUCTS</h3>
<p>The following versions of Yokogawa STARDOM FCN/FCJ, a network control system, are affected:</p>
<ul><li>STARDOM FCN/FCJ: versions R1.01 through R4.31</li>
</ul><h3>3.2 Vulnerability Overview</h3>
<h4>3.2.1 <a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank">UNCONTROLLED RESOURCE CONSUMPTION CWE-400</a></h4>
<p>This vulnerability may allow to a remote attacker to cause a denial-of-service condition to the FCN/FCJ controller by sending a crafted packet. While sending the packet, the maintenance homepage of the controller could not be accessed. Therefore, functions of the maintenance homepage, changing configuration, viewing logs, etc. are not available. But the controller's operation is not stopped by the condition.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-5915" target="_blank">CVE-2023-5915</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank">AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</a>).</p>
<h3>3.3 BACKGROUND</h3>
<ul><li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Multiple</li>
<li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li>
<li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Japan</li>
</ul><h3>3.4 RESEARCHER</h3>
<p>Roman Ezhov of Kaspersky reported this vulnerability to Yokogawa.</p>
<h2>4. MITIGATIONS</h2>
<p>Yokogawa has released the following mitigations for users to implement:</p>
<ul><li>By using the packet filter function* of the FCN/FCJ controller, only allow connection from trusted hosts.</li>
<li>Take measures against the network so that an attacker cannot send a malicious packet.</li>
</ul><p>Yokogawa strongly recommends all users to establish and maintain a full security program, not only for the vulnerability identified in this YSAR. Security program components are: Patch updates, Anti-virus, Backup and recovery, zoning, hardening, whitelisting, firewall, etc. Yokogawa can assist in setting up and running the security program continuously. For considering the most effective risk mitigation plan, as a starting point, Yokogawa can perform a security risk assessment.</p>
<p>*Revision up FCN/FCJ basic software to R4.20 or later for using the function.</p>
<p>More details can also be found in Yokogawa's security advisory report number <a href="https://web-material3.yokogawa.com/1/29820/files/YSAR-23-0003.pdf" target="_blank">YSAR-23-0003.</a></p>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:</p>
<ul><li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li>
<li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li>
<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li>
</ul><p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>
<h2>5. UPDATE HISTORY</h2>
<ul><li>November 30, 2023: Initial Publication</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Releases Four Industrial Control Systems Advisories]]></title>
<description><![CDATA[CISA released four Industrial Control Systems (ICS) advisories on November 30, 2023. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
ICSA-23-334-01 Delta Electronics DOPSoft
ICSA-23-334-02 Yokogawa STARDOM
ICSA-23-334-03 PT...]]></description>
<link>https://tsecurity.de/de/1946296/it-security-nachrichten/cisa-releases-four-industrial-control-systems-advisories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1946296/it-security-nachrichten/cisa-releases-four-industrial-control-systems-advisories/</guid>
<pubDate>Thu, 30 Nov 2023 17:05:55 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>CISA released four Industrial Control Systems (ICS) advisories on November 30, 2023. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.</p>
<ul><li>ICSA-23-334-01 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-23-334-01">Delta Electronics DOPSoft</a></li>
<li>ICSA-23-334-02 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-23-334-02">Yokogawa STARDOM</a></li>
<li>ICSA-23-334-03 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-23-334-03">PTC KEPServerEx</a></li>
<li>ICSA-23-334-04 <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-23-334-04">Mitsubishi Electric FA Engineering Software Products</a></li>
</ul><p>CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-26593 | Yokogawa CENTUM cleartext storage]]></title>
<description><![CDATA[A vulnerability was found in Yokogawa CENTUM and classified as problematic. This issue affects some unknown processing. The manipulation leads to cleartext storage of sensitive information.

The identification of this vulnerability is CVE-2023-26593. The attack needs to be done within the local n...]]></description>
<link>https://tsecurity.de/de/1882305/sicherheitsluecken/cve-2023-26593-yokogawa-centum-cleartext-storage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1882305/sicherheitsluecken/cve-2023-26593-yokogawa-centum-cleartext-storage/</guid>
<pubDate>Wed, 26 Apr 2023 23:37:09 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.yokogawa:centum">Yokogawa CENTUM</a> and classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. This issue affects some unknown processing. The manipulation leads to cleartext storage of sensitive information.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.225473">CVE-2023-26593</a>. The attack needs to be done within the local network. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-26593]]></title>
<description><![CDATA[CENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensitive information. If an attacker who can login or access the computer where the affected product is installed tampers the password file stored in the computer, the user privilege which CENTUM manag...]]></description>
<link>https://tsecurity.de/de/1856986/sicherheitsluecken/cve-2023-26593/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1856986/sicherheitsluecken/cve-2023-26593/</guid>
<pubDate>Tue, 11 Apr 2023 18:53:23 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[CENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensitive information. If an attacker who can login or access the computer where the affected product is installed tampers the password file stored in the computer, the user privilege which CENTUM managed may be escalated. As a result, the control system may be operated with the escalated user privilege. To exploit this vulnerability, the following prerequisites must be met: (1)An attacker has obtained user credentials where the affected product is installed, (2)CENTUM Authentication Mode is used for user authentication when CENTUM VP is used. The affected products and versions are as follows: CENTUM CS 1000, CENTUM CS 3000 (Including CENTUM CS 3000 Entry Class) R2.01.00 to R3.09.50, CENTUM VP (Including CENTUM VP Entry Class) R4.01.00 to R4.03.00, R5.01.00 to R5.04.20, and R6.01.00 and later, B/M9000 CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R7.04.51 and R8.01.01 and later]]></content:encoded>
</item>
<item>
<title><![CDATA[Waterfall Security Solutions partners with Yokogawa to improve industrial security]]></title>
<description><![CDATA[Waterfall Security Solutions announced a collaboration agreement with Yokogawa, a provider of industrial automation and test and measurement solutions. This new collaboration will make Waterfall’s Unidirectional Gateway cybersecurity products and technologies available to Yokogawa’s customers glo...]]></description>
<link>https://tsecurity.de/de/1764212/it-security-nachrichten/waterfall-security-solutions-partners-with-yokogawa-to-improve-industrial-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1764212/it-security-nachrichten/waterfall-security-solutions-partners-with-yokogawa-to-improve-industrial-security/</guid>
<pubDate>Wed, 11 Jan 2023 01:45:49 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Waterfall Security Solutions announced a collaboration agreement with Yokogawa, a provider of industrial automation and test and measurement solutions. This new collaboration will make Waterfall’s Unidirectional Gateway cybersecurity products and technologies available to Yokogawa’s customers globally. In a world where cyber threats to industrial operations continue to become more powerful and more pervasive, making unidirectional protections available more widely will dramatically improve industrial security programs and preparedness. “Operational and technical reliability is a key focus … <a href="https://www.helpnetsecurity.com/2023/01/11/waterfall-security-solutions-yokogawa/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a rel="nofollow" href="https://www.helpnetsecurity.com/2023/01/11/waterfall-security-solutions-yokogawa/">Waterfall Security Solutions partners with Yokogawa to improve industrial security</a> appeared first on <a rel="nofollow" href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-40984 | Yokogawa WTViewerE/WTViewerEfree Filename stack-based overflow]]></title>
<description><![CDATA[A vulnerability was found in Yokogawa WTViewerE and WTViewerEfree. It has been classified as problematic. This affects an unknown part of the component Filename Handler. The manipulation leads to stack-based buffer overflow.

This vulnerability is uniquely identified as CVE-2022-40984. The attack...]]></description>
<link>https://tsecurity.de/de/1700912/sicherheitsluecken/cve-2022-40984-yokogawa-wtviewerewtviewerefree-filename-stack-based-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1700912/sicherheitsluecken/cve-2022-40984-yokogawa-wtviewerewtviewerefree-filename-stack-based-overflow/</guid>
<pubDate>Sat, 19 Nov 2022 16:49:14 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.yokogawa:wtviewere">Yokogawa WTViewerE and WTViewerEfree</a>. It has been classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. This affects an unknown part of the component <em>Filename Handler</em>. The manipulation leads to stack-based buffer overflow.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.212037">CVE-2022-40984</a>. The attack needs to be approached within the local network. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Echtzeitschutz: Yokogawa bringt IT/OT Security Operations Center Service auf den Markt]]></title>
<description><![CDATA[Die Echtzeitüberwachung von Netzwerken und IT/OT-Infrastrukturen auf Cybersecurity-Bedrohungen bietet den Kunden einen umfassenden Schutz, der sowohl ...]]></description>
<link>https://tsecurity.de/de/1630620/it-security-nachrichten/echtzeitschutz-yokogawa-bringt-itot-security-operations-center-service-auf-den-markt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1630620/it-security-nachrichten/echtzeitschutz-yokogawa-bringt-itot-security-operations-center-service-auf-den-markt/</guid>
<pubDate>Wed, 14 Sep 2022 12:33:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Echtzeitüberwachung von Netzwerken und <b>IT</b>/OT-Infrastrukturen auf Cybersecurity-Bedrohungen bietet den Kunden einen umfassenden Schutz, der sowohl ...]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-33939 | Yokogawa CENTUM Controller Packet resource consumption]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in  Yokogawa CENTUM Controller. This issue affects some unknown processing of the component Packet Handler. The manipulation leads to resource consumption.

The identification of this vulnerability is CVE-2022-33939. The attack ...]]></description>
<link>https://tsecurity.de/de/1627377/sicherheitsluecken/cve-2022-33939-yokogawa-centum-controller-packet-resource-consumption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1627377/sicherheitsluecken/cve-2022-33939-yokogawa-centum-controller-packet-resource-consumption/</guid>
<pubDate>Sun, 11 Sep 2022 17:01:33 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as problematic, has been found in  Yokogawa CENTUM Controller. This issue affects some unknown processing of the component <em>Packet Handler</em>. The manipulation leads to resource consumption.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.206453">CVE-2022-33939</a>. The attack may be initiated remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-34866 | Yokogawa Passage Drive up to 1.0.0/1.4.0/1.5.1.0 Interprocess Communication os command injection]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in  Yokogawa Passage Drive up to 1.0.0/1.4.0/1.5.1.0. Affected is an unknown function of the component Interprocess Communication Handler. The manipulation leads to os command injection.

This vulnerability is traded as CVE-2022-34866. ...]]></description>
<link>https://tsecurity.de/de/1601496/sicherheitsluecken/cve-2022-34866-yokogawa-passage-drive-up-to-1001401510-interprocess-communication-os-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1601496/sicherheitsluecken/cve-2022-34866-yokogawa-passage-drive-up-to-1001401510-interprocess-communication-os-command-injection/</guid>
<pubDate>Mon, 15 Aug 2022 11:49:23 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as critical, was found in  Yokogawa Passage Drive up to 1.0.0/1.4.0/1.5.1.0. Affected is an unknown function of the component <em>Interprocess Communication Handler</em>. The manipulation leads to os command injection.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.204582">CVE-2022-34866</a>. It is possible to launch the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-32284 | Yokogawa AW810D VI461 denial of service (icsa-22-181-02)]]></title>
<description><![CDATA[A vulnerability was found in  Yokogawa AW810D. It has been classified as critical. This affects an unknown part of the component VI461. The manipulation leads to denial of service.

This vulnerability is uniquely identified as CVE-2022-32284. It is possible to initiate the attack remotely. There ...]]></description>
<link>https://tsecurity.de/de/1574479/sicherheitsluecken/cve-2022-32284-yokogawa-aw810d-vi461-denial-of-service-icsa-22-181-02/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1574479/sicherheitsluecken/cve-2022-32284-yokogawa-aw810d-vi461-denial-of-service-icsa-22-181-02/</guid>
<pubDate>Mon, 18 Jul 2022 13:17:23 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in  Yokogawa AW810D. It has been classified as critical. This affects an unknown part of the component <em>VI461</em>. The manipulation leads to denial of service.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.203181">CVE-2022-32284</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-30997 | Yokogawa STARDOM FCN Controller/STARDOM FCJ Controller up to R4.31 hard-coded credentials (icsa-22-174-01)]]></title>
<description><![CDATA[A vulnerability classified as very critical has been found in  Yokogawa STARDOM FCN Controller and STARDOM FCJ Controller up to R4.31. Affected is an unknown function. The manipulation leads to hard-coded credentials.

This vulnerability is traded as CVE-2022-30997. It is possible to launch the a...]]></description>
<link>https://tsecurity.de/de/1573034/sicherheitsluecken/cve-2022-30997-yokogawa-stardom-fcn-controllerstardom-fcj-controller-up-to-r431-hard-coded-credentials-icsa-22-174-01/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1573034/sicherheitsluecken/cve-2022-30997-yokogawa-stardom-fcn-controllerstardom-fcj-controller-up-to-r431-hard-coded-credentials-icsa-22-174-01/</guid>
<pubDate>Sat, 16 Jul 2022 11:17:03 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as very critical has been found in  Yokogawa STARDOM FCN Controller and STARDOM FCJ Controller up to R4.31. Affected is an unknown function. The manipulation leads to hard-coded credentials.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.202914">CVE-2022-30997</a>. It is possible to launch the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-29519 | Yokogawa STARDOM FCN Controller/STARDOM FCJ Controller up to R4.31 cleartext transmission (icsa-22-174-01)]]></title>
<description><![CDATA[A vulnerability was found in  Yokogawa STARDOM FCN Controller and STARDOM FCJ Controller up to R4.31. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cleartext transmission of sensitive information.

The identification of this vulnerability ...]]></description>
<link>https://tsecurity.de/de/1573035/sicherheitsluecken/cve-2022-29519-yokogawa-stardom-fcn-controllerstardom-fcj-controller-up-to-r431-cleartext-transmission-icsa-22-174-01/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1573035/sicherheitsluecken/cve-2022-29519-yokogawa-stardom-fcn-controllerstardom-fcj-controller-up-to-r431-cleartext-transmission-icsa-22-174-01/</guid>
<pubDate>Sat, 16 Jul 2022 11:17:03 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in  Yokogawa STARDOM FCN Controller and STARDOM FCJ Controller up to R4.31. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cleartext transmission of sensitive information.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.202913">CVE-2022-29519</a>. The attack may be initiated remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-30707 | Yokogawa CENTUM CAMS information disclosure (icsa-22-174-02)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in  Yokogawa CENTUM. Affected is an unknown function of the component CAMS. The manipulation leads to information disclosure.

This vulnerability is traded as CVE-2022-30707. The attack can only be initiated within the local network....]]></description>
<link>https://tsecurity.de/de/1572959/sicherheitsluecken/cve-2022-30707-yokogawa-centum-cams-information-disclosure-icsa-22-174-02/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1572959/sicherheitsluecken/cve-2022-30707-yokogawa-centum-cams-information-disclosure-icsa-22-174-02/</guid>
<pubDate>Sat, 16 Jul 2022 08:49:13 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as problematic, was found in  Yokogawa CENTUM. Affected is an unknown function of the component <em>CAMS</em>. The manipulation leads to information disclosure.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.202890">CVE-2022-30707</a>. The attack can only be initiated within the local network. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-32284]]></title>
<description><![CDATA[Use of insufficiently random values vulnerability exists in Vnet/IP communication module VI461 of YOKOGAWA Wide Area Communication Router (WAC Router) AW810D, which may allow a remote attacker to cause denial-of-service (DoS) condition by sending a specially crafted packet.]]></description>
<link>https://tsecurity.de/de/1559746/sicherheitsluecken/cve-2022-32284/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1559746/sicherheitsluecken/cve-2022-32284/</guid>
<pubDate>Mon, 04 Jul 2022 05:17:59 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Use of insufficiently random values vulnerability exists in Vnet/IP communication module VI461 of YOKOGAWA Wide Area Communication Router (WAC Router) AW810D, which may allow a remote attacker to cause denial-of-service (DoS) condition by sending a specially crafted packet.]]></content:encoded>
</item>
<item>
<title><![CDATA[Researchers Disclose 56 Vulnerabilities Impacting OT Devices from 10 Vendors]]></title>
<description><![CDATA[Nearly five dozen security vulnerabilities have been disclosed in devices from 10 operational technology (OT) vendors due to what researchers call are "insecure-by-design practices."
Collectively dubbed OT:ICEFALL by Forescout, the 56 issues span as many as 26 device models from Bently Nevada, Em...]]></description>
<link>https://tsecurity.de/de/1547445/it-security-nachrichten/researchers-disclose-56-vulnerabilities-impacting-ot-devices-from-10-vendors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1547445/it-security-nachrichten/researchers-disclose-56-vulnerabilities-impacting-ot-devices-from-10-vendors/</guid>
<pubDate>Tue, 21 Jun 2022 11:33:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Nearly five dozen security vulnerabilities have been disclosed in devices from 10 operational technology (OT) vendors due to what researchers call are "insecure-by-design practices."
Collectively dubbed OT:ICEFALL by Forescout, the 56 issues span as many as 26 device models from Bently Nevada, Emerson, Honeywell, JTEKT, Motorola, Omron, Phoenix Contact, Siemens, and Yokogawa.
"Exploiting these]]></content:encoded>
</item>
<item>
<title><![CDATA[Researchers disclose 56 vulnerabilities impacting thousands of OT devices]]></title>
<description><![CDATA[Forescout’s Vedere Labs disclosed OT:ICEFALL, 56 vulnerabilities affecting devices from 10 operational technology (OT) vendors. This is one of the single largest vulnerability disclosures that impact OT devices and directly addresses insecure-by-design vulnerabilities. In this video for Help Net ...]]></description>
<link>https://tsecurity.de/de/1546970/it-security-nachrichten/researchers-disclose-56-vulnerabilities-impacting-thousands-of-ot-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1546970/it-security-nachrichten/researchers-disclose-56-vulnerabilities-impacting-thousands-of-ot-devices/</guid>
<pubDate>Tue, 21 Jun 2022 04:33:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Forescout’s Vedere Labs disclosed OT:ICEFALL, 56 vulnerabilities affecting devices from 10 operational technology (OT) vendors. This is one of the single largest vulnerability disclosures that impact OT devices and directly addresses insecure-by-design vulnerabilities. In this video for Help Net Security, Daniel dos Santos, Head of Security Research, Forescout, talks about the 56 vulnerabilities, which impact ten vendors, including Bently Nevada, Emerson, Honeywell, JTEKT, Motorola, Omron, Phoenix Contact, Siemens, and Yokogawa. Devices affected by OT:ICEFALL Bently … <a href="https://www.helpnetsecurity.com/2022/06/21/vulnerabilities-ot-devices-icefall/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a rel="nofollow" href="https://www.helpnetsecurity.com/2022/06/21/vulnerabilities-ot-devices-icefall/">Researchers disclose 56 vulnerabilities impacting thousands of OT devices</a> appeared first on <a rel="nofollow" href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa erhält ISASecure-Zertifizierung für sicherheitsgerichtete Steuerung ProSafe-RS]]></title>
<description><![CDATA[Es entspricht den internationalen Normen IEC 62443-4-2 und IEC 62443-4-1 der Internationalen Elektrotechnischen Kommission für die IT-Sicherheit ...]]></description>
<link>https://tsecurity.de/de/1492137/it-security-nachrichten/yokogawa-erhaelt-isasecure-zertifizierung-fuer-sicherheitsgerichtete-steuerung-prosafe-rs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1492137/it-security-nachrichten/yokogawa-erhaelt-isasecure-zertifizierung-fuer-sicherheitsgerichtete-steuerung-prosafe-rs/</guid>
<pubDate>Thu, 03 Jun 2021 01:30:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Es entspricht den internationalen Normen IEC 62443-4-2 und IEC 62443-4-1 der Internationalen Elektrotechnischen Kommission für die <b>IT</b>-<b>Sicherheit</b> ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Claroty und Yokogawa stärken gemeinsam die Cybersicherheit bei industriellen Prozessabläufen]]></title>
<description><![CDATA[So verbessert die Claroty-Plattform die OT-Sicherheit, indem sie ... Claroty schließt die Lücke in der industriellen Cybersicherheit zwischen IT und OT.]]></description>
<link>https://tsecurity.de/de/1249866/it-security-nachrichten/claroty-und-yokogawa-staerken-gemeinsam-die-cybersicherheit-bei-industriellen-prozessablaeufen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1249866/it-security-nachrichten/claroty-und-yokogawa-staerken-gemeinsam-die-cybersicherheit-bei-industriellen-prozessablaeufen/</guid>
<pubDate>Mon, 28 Sep 2020 18:31:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[So verbessert die Claroty-Plattform die OT-<b>Sicherheit</b>, indem sie ... Claroty schließt die Lücke in der industriellen Cybersicherheit zwischen <b>IT</b> und OT.]]></content:encoded>
</item>
<item>
<title><![CDATA[Claroty und Yokogawa stärken gemeinsam die Cybersicherheit bei industriellen Prozessabläufen]]></title>
<description><![CDATA[So verbessert die Claroty-Plattform die OT-Sicherheit, indem sie ... Claroty schließt die Lücke in der industriellen Cybersicherheit zwischen IT und OT.]]></description>
<link>https://tsecurity.de/de/1249867/it-security-nachrichten/claroty-und-yokogawa-staerken-gemeinsam-die-cybersicherheit-bei-industriellen-prozessablaeufen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1249867/it-security-nachrichten/claroty-und-yokogawa-staerken-gemeinsam-die-cybersicherheit-bei-industriellen-prozessablaeufen/</guid>
<pubDate>Mon, 28 Sep 2020 18:31:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[So verbessert die Claroty-Plattform die OT-<b>Sicherheit</b>, indem sie ... Claroty schließt die Lücke in der industriellen Cybersicherheit zwischen <b>IT</b> und OT.]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa erhält ISASecure® SDLA-Zertifizierung]]></title>
<description><![CDATA[Cybersecurity in Industrieanlagen über den gesamten Lebenszyklus hinweg. (PresseBox) ( Ratingen, 13.05.20 ). Die Yokogawa Electric Corporation hat ...]]></description>
<link>https://tsecurity.de/de/1115656/it-security-nachrichten/yokogawa-erhaelt-isasecure-sdla-zertifizierung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1115656/it-security-nachrichten/yokogawa-erhaelt-isasecure-sdla-zertifizierung/</guid>
<pubDate>Wed, 13 May 2020 17:02:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity in Industrieanlagen über den gesamten Lebenszyklus hinweg. (PresseBox) ( Ratingen, 13.05.20 ). Die Yokogawa Electric Corporation hat ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa B-M9000 License Manager Service privilege escalation]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Yokogawa CENTUM VP, CENTUM VP Entry Class, ProSafe-RS, PRM and B-M9000. Affected by this vulnerability is an unknown function of the component License Manager Service. There is no information about possible countermeasures known. It may be sugge...]]></description>
<link>https://tsecurity.de/de/1112219/sicherheitsluecken/yokogawa-b-m9000-license-manager-service-privilege-escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1112219/sicherheitsluecken/yokogawa-b-m9000-license-manager-service-privilege-escalation/</guid>
<pubDate>Sun, 10 May 2020 16:02:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as critical was found in <a href="https://vuldb.com/?product.yokogawa:centum_vp">Yokogawa CENTUM VP, CENTUM VP Entry Class, ProSafe-RS, PRM and B-M9000</a>. Affected by this vulnerability is an unknown function of the component <em>License Manager Service</em>. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa CENTUM CS 3000 denial of service [CVE-2018-16196]]]></title>
<description><![CDATA[A vulnerability was found in Yokogawa CENTUM CS 3000 (affected version unknown). It has been declared as problematic. Affected by this vulnerability is an unknown function. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alt...]]></description>
<link>https://tsecurity.de/de/1098956/sicherheitsluecken/yokogawa-centum-cs-3000-denial-of-service-cve-2018-16196/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1098956/sicherheitsluecken/yokogawa-centum-cs-3000-denial-of-service-cve-2018-16196/</guid>
<pubDate>Mon, 27 Apr 2020 18:48:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.yokogawa:centum_cs_3000">Yokogawa CENTUM CS 3000</a> (<a href="https://vuldb.com/?doc.version">affected version unknown</a>). It has been declared as problematic. Affected by this vulnerability is an unknown function. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa iDefine for ProSafe-RS License Management memory corruption]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Yokogawa iDefine for ProSafe-RS, STARDOM VDS, STARDOM FCN, STARDOM FCJ, ASTRAPLANNER and TriFellows. This issue affects an unknown code block of the component License Management. There is no information about possible countermea...]]></description>
<link>https://tsecurity.de/de/1098254/sicherheitsluecken/yokogawa-idefine-for-prosafe-rs-license-management-memory-corruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1098254/sicherheitsluecken/yokogawa-idefine-for-prosafe-rs-license-management-memory-corruption/</guid>
<pubDate>Mon, 27 Apr 2020 10:03:41 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as critical, has been found in <a href="https://vuldb.com/?product.yokogawa:idefine_for_prosafe-rs">Yokogawa iDefine for ProSafe-RS, STARDOM VDS, STARDOM FCN, STARDOM FCJ, ASTRAPLANNER and TriFellows</a>. This issue affects an unknown code block of the component <em>License Management</em>. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa STARDOM Controllers up to R4.10 Session Management denial of service]]></title>
<description><![CDATA[A vulnerability has been found in Yokogawa STARDOM Controllers up to R4.10 and classified as problematic. This vulnerability affects an unknown code block of the component Session Management. There is no information about possible countermeasures known. It may be suggested to replace the affected...]]></description>
<link>https://tsecurity.de/de/1073246/sicherheitsluecken/yokogawa-stardom-controllers-up-to-r410-session-management-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1073246/sicherheitsluecken/yokogawa-stardom-controllers-up-to-r410-session-management-denial-of-service/</guid>
<pubDate>Thu, 02 Apr 2020 10:17:51 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/?product.yokogawa:stardom_controllers">Yokogawa STARDOM Controllers up to R4.10</a> and classified as problematic. This vulnerability affects an unknown code block of the component <em>Session Management</em>. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa STARDOM Controllers up to R4.10 Web Application Credentials information disclosure]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Yokogawa STARDOM Controllers up to R4.10. This affects an unknown code of the component Web Application. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alte...]]></description>
<link>https://tsecurity.de/de/1073247/sicherheitsluecken/yokogawa-stardom-controllers-up-to-r410-web-application-credentials-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1073247/sicherheitsluecken/yokogawa-stardom-controllers-up-to-r410-web-application-credentials-information-disclosure/</guid>
<pubDate>Thu, 02 Apr 2020 10:17:51 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as problematic, was found in <a href="https://vuldb.com/?product.yokogawa:stardom_controllers">Yokogawa STARDOM Controllers up to R4.10</a>. This affects an unknown code of the component <em>Web Application</em>. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa STARDOM Controller up to R4.10 Memory Exhaustion denial of service]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Yokogawa STARDOM Controller up to R4.10. Affected by this issue is an unknown part. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.]]></description>
<link>https://tsecurity.de/de/1073248/sicherheitsluecken/yokogawa-stardom-controller-up-to-r410-memory-exhaustion-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1073248/sicherheitsluecken/yokogawa-stardom-controller-up-to-r410-memory-exhaustion-denial-of-service/</guid>
<pubDate>Thu, 02 Apr 2020 10:17:51 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as problematic, has been found in <a href="https://vuldb.com/?product.yokogawa:stardom_controller">Yokogawa STARDOM Controller up to R4.10</a>. Affected by this issue is an unknown part. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa STARDOM Controller up to R4.10 Default Credentials weak authentication]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Yokogawa STARDOM Controller up to R4.10. Affected by this vulnerability is some unknown functionality. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.]]></description>
<link>https://tsecurity.de/de/1073249/sicherheitsluecken/yokogawa-stardom-controller-up-to-r410-default-credentials-weak-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1073249/sicherheitsluecken/yokogawa-stardom-controller-up-to-r410-default-credentials-weak-authentication/</guid>
<pubDate>Thu, 02 Apr 2020 10:17:51 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as critical was found in <a href="https://vuldb.com/?product.yokogawa:stardom_controller">Yokogawa STARDOM Controller up to R4.10</a>. Affected by this vulnerability is some unknown functionality. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa STARDOM FCN-500 up to R4.02 Default Credentials weak authentication]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Yokogawa STARDOM FCJ, STARDOM FCN-100, STARDOM FCN-RTU and STARDOM FCN-500 up to R4.02. Affected by this vulnerability is an unknown functionality. There is no information about possible countermeasures known. It may be suggested to replace the ...]]></description>
<link>https://tsecurity.de/de/1049208/sicherheitsluecken/yokogawa-stardom-fcn-500-up-to-r402-default-credentials-weak-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1049208/sicherheitsluecken/yokogawa-stardom-fcn-500-up-to-r402-default-credentials-weak-authentication/</guid>
<pubDate>Wed, 11 Mar 2020 14:03:23 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as critical was found in <a href="https://vuldb.com/?product.yokogawa:stardom_fcj">Yokogawa STARDOM FCJ, STARDOM FCN-100, STARDOM FCN-RTU and STARDOM FCN-500 up to R4.02</a>. Affected by this vulnerability is an unknown functionality. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.]]></content:encoded>
</item>
<item>
<title><![CDATA[High Severity DoS bug affects Several Yokogawa products]]></title>
<description><![CDATA[A serious DoS flaw affects several industrial automation products manufactured by the Yokogawa Electric. The DoS vulnerability in several Yokogawa Electric products affects the Open Communication Driver for Vnet/IP, a real-time plant network system for process automation. The flaw, tracked as CVE...]]></description>
<link>https://tsecurity.de/de/441921/hacking/high-severity-dos-bug-affects-several-yokogawa-products/</link>
<guid isPermaLink="true">https://tsecurity.de/de/441921/hacking/high-severity-dos-bug-affects-several-yokogawa-products/</guid>
<pubDate>Sat, 05 Jan 2019 11:45:38 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<p>A serious DoS flaw affects several industrial automation products manufactured by the Yokogawa Electric. The DoS vulnerability in several Yokogawa Electric products affects the Open Communication Driver for Vnet/IP, a real-time plant network system for process automation. The flaw, tracked as CVE-2018-16196, could be exploited by an attacker to stop communication function of Vnet/IP Open Communication […]</p>
<p>The post <a rel="nofollow" href="https://securityaffairs.co/wordpress/79515/security/dos-yokogawa-electric.html">High Severity DoS bug affects Several Yokogawa products</a> appeared first on <a rel="nofollow" href="https://securityaffairs.co/wordpress">Security Affairs</a>.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Serious DoS Flaw Impacts Several Yokogawa Products]]></title>
<description><![CDATA[A serious denial-of-service (DoS) vulnerability impacts several industrial automation products from Japanese electrical engineering and software company Yokogawa Electric.
read more]]></description>
<link>https://tsecurity.de/de/441570/it-security-nachrichten/serious-dos-flaw-impacts-several-yokogawa-products/</link>
<guid isPermaLink="true">https://tsecurity.de/de/441570/it-security-nachrichten/serious-dos-flaw-impacts-several-yokogawa-products/</guid>
<pubDate>Fri, 04 Jan 2019 17:17:25 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<p><strong><span><span>A serious denial-of-service (DoS) vulnerability impacts several industrial automation products from Japanese electrical engineering and software company Yokogawa Electric.</span></span></strong></p>
<p><a href="https://www.securityweek.com/serious-dos-flaw-impacts-several-yokogawa-products" target="_blank">read more</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Securityweek?a=Pnvu40-CQMI:QkQ4vQ14i20:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Securityweek?d=yIl2AUoC8zA" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=Pnvu40-CQMI:QkQ4vQ14i20:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/Securityweek?i=Pnvu40-CQMI:QkQ4vQ14i20:-BTjWOF_DHI" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=Pnvu40-CQMI:QkQ4vQ14i20:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/Securityweek?d=dnMXMwOfBR0" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=Pnvu40-CQMI:QkQ4vQ14i20:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Securityweek?i=Pnvu40-CQMI:QkQ4vQ14i20:V_sGLiPBpWU" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=Pnvu40-CQMI:QkQ4vQ14i20:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Securityweek?d=qj6IDK7rITs" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=Pnvu40-CQMI:QkQ4vQ14i20:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Securityweek?i=Pnvu40-CQMI:QkQ4vQ14i20:gIN9vFwOqvQ" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=Pnvu40-CQMI:QkQ4vQ14i20:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/Securityweek?d=TzevzKxY174" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=Pnvu40-CQMI:QkQ4vQ14i20:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Securityweek?i=Pnvu40-CQMI:QkQ4vQ14i20:F7zBnMyn0Lo" border="0"></a>
</div>
<img src="http://feeds.feedburner.com/~r/Securityweek/~4/Pnvu40-CQMI" height="1" width="1" alt="">
]]></content:encoded>
</item>
<item>
<title><![CDATA[Vuln: Yokogawa Vnet/IP Open Communication Driver CVE-2018-16196 Denial of Service Vulnerability]]></title>
<description><![CDATA[Yokogawa Vnet/IP Open Communication Driver CVE-2018-16196 Denial of Service Vulnerability]]></description>
<link>https://tsecurity.de/de/441158/sicherheitsluecken/vuln-yokogawa-vnetip-open-communication-driver-cve-2018-16196-denial-of-service-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/441158/sicherheitsluecken/vuln-yokogawa-vnetip-open-communication-driver-cve-2018-16196-denial-of-service-vulnerability/</guid>
<pubDate>Fri, 04 Jan 2019 10:12:36 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Yokogawa Vnet/IP Open Communication Driver CVE-2018-16196 Denial of Service Vulnerability]]></content:encoded>
</item>
<item>
<title><![CDATA[Severe Flaws Found in Yokogawa Switches, Control Systems]]></title>
<description><![CDATA[Japanese electrical engineering company Yokogawa published two security advisories last week to inform customers that some of its products are affected by serious vulnerabilities.
read more]]></description>
<link>https://tsecurity.de/de/361192/it-security-nachrichten/severe-flaws-found-in-yokogawa-switches-control-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/361192/it-security-nachrichten/severe-flaws-found-in-yokogawa-switches-control-systems/</guid>
<pubDate>Thu, 23 Aug 2018 19:30:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<p><strong><span><span>Japanese electrical engineering company Yokogawa published two security advisories last week to inform customers that some of its products are affected by serious vulnerabilities.</span></span></strong></p>
<p><a href="https://www.securityweek.com/severe-flaws-found-yokogawa-switches-control-systems" target="_blank">read more</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Securityweek?a=7iCz38x-nD0:x4j1ah87XN8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Securityweek?d=yIl2AUoC8zA" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=7iCz38x-nD0:x4j1ah87XN8:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/Securityweek?i=7iCz38x-nD0:x4j1ah87XN8:-BTjWOF_DHI" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=7iCz38x-nD0:x4j1ah87XN8:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/Securityweek?d=dnMXMwOfBR0" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=7iCz38x-nD0:x4j1ah87XN8:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Securityweek?i=7iCz38x-nD0:x4j1ah87XN8:V_sGLiPBpWU" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=7iCz38x-nD0:x4j1ah87XN8:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Securityweek?d=qj6IDK7rITs" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=7iCz38x-nD0:x4j1ah87XN8:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Securityweek?i=7iCz38x-nD0:x4j1ah87XN8:gIN9vFwOqvQ" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=7iCz38x-nD0:x4j1ah87XN8:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/Securityweek?d=TzevzKxY174" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=7iCz38x-nD0:x4j1ah87XN8:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Securityweek?i=7iCz38x-nD0:x4j1ah87XN8:F7zBnMyn0Lo" border="0"></a>
</div>
<img src="http://feeds.feedburner.com/~r/Securityweek/~4/7iCz38x-nD0" height="1" width="1" alt="">
]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa STARDOM FCN-500 bis R4.02 Default Credentials schwache Authentisierung]]></title>
<description><![CDATA[In Yokogawa STARDOM FCJ, STARDOM FCN-100, STARDOM FCN-RTU sowie STARDOM FCN-500 bis R4.02 wurde eine kritische Schwachstelle entdeckt. Betroffen ist eine unbekannte Funktion. Mittels dem Manipulieren mit einer unbekannten Eingabe kann eine schwache Authentisierung-Schwachstelle (Default Credentia...]]></description>
<link>https://tsecurity.de/de/349634/sicherheitsluecken/yokogawa-stardom-fcn-500-bis-r402-default-credentials-schwache-authentisierung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/349634/sicherheitsluecken/yokogawa-stardom-fcn-500-bis-r402-default-credentials-schwache-authentisierung/</guid>
<pubDate>Wed, 01 Aug 2018 09:19:52 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<p>In Yokogawa STARDOM FCJ, STARDOM FCN-100, STARDOM FCN-RTU sowie STARDOM FCN-500 bis R4.02 wurde eine kritische Schwachstelle entdeckt. Betroffen ist eine unbekannte Funktion. Mittels dem Manipulieren mit einer unbekannten Eingabe kann eine schwache Authentisierung-Schwachstelle (Default Credentials) ausgenutzt werden. CWE definiert das Problem als <a href="https://cwe.mitre.org/data/definitions/798.html">CWE-798</a>. Die Auswirkungen sind bekannt für Vertraulichkeit, Integrität und Verfügbarkeit. </p>
<p>Die Schwachstelle wurde am 31.07.2018 öffentlich gemacht. Die Verwundbarkeit wird seit dem 01.05.2018 als <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10592">CVE-2018-10592</a> geführt. Um eine Ausnutzung durchzusetzen, muss keine spezifische Authentisierung umgesetzt werden. Technische Details sind nicht bekannt und ein Exploit zur Schwachstelle ist ebenfalls nicht vorhanden. Die Beschaffenheit der Schwachstelle lässt vermuten, dass ein Exploit momentan zu etwa USD $0-$5k gehandelt werden wird (<a href="https://vuldb.com/?doc.exploitprices">Preisberechnung vom 08/01/2018</a>). </p>
<p></p>
<p>Es sind keine Informationen bezüglich Gegenmassnahmen bekannt. Der Einsatz eines alternativen Produkts bietet sich im Zweifelsfall an.</p>
<p></p>
<h2>CPE</h2>
<ul>
<li><span><a href="https://vuldb.com/?login">?</a></span></li>
<li><span><a href="https://vuldb.com/?login">?</a></span></li>
<li><span><a href="https://vuldb.com/?login">?</a></span></li>
</ul>
<h2>CVSSv3</h2>
<span>VulDB Meta Base Score</span>: 6.3<br><span>VulDB Meta Temp Score</span>: 6.3<br><br><span>VulDB Base Score</span>: <a href="https://www.first.org/cvss/specification-document#2-Base-Metrics">6.3</a><br><span>VulDB Temp Score</span>: <a href="https://www.first.org/cvss/specification-document#3-Temporal-Metrics">6.3</a><br><span>VulDB Vector</span>: <span><a href="https://vuldb.com/?login">?</a></span><br><span>VulDB Zuverlässigkeit</span>: <span><a href="https://vuldb.com/?doc.purchase">?</a></span><h2>CVSSv2</h2>
<span>VulDB Base Score</span>: <span><a href="https://vuldb.com/?login">?</a></span><br><span>VulDB Temp Score</span>: <span><a href="https://vuldb.com/?login">?</a></span><br><span>VulDB Zuverlässigkeit</span>: <span><a href="https://vuldb.com/?doc.purchase">?</a></span><br><h2>Exploiting</h2>
<span>Klasse</span>: Schwache Authentisierung / Default Credentials (<a href="https://cwe.mitre.org/data/definitions/798.html">CWE-798</a>)<br><span>Lokal</span>: Ja<br><span>Remote</span>: Nein<br><br><span>Verfügbarkeit</span>: Nein<br><br><span>Preisentwicklung</span>: <span><a href="https://vuldb.com/?doc.purchase">?</a></span><br><span>Aktuelle Preisschätzung</span>: <span><a href="https://vuldb.com/?login">?</a></span><h2>Threat Intelligence</h2>
<span>Bedrohungslage</span>: <span><a href="https://vuldb.com/?doc.purchase">?</a></span><br><span>Gegner</span>: <span><a href="https://vuldb.com/?doc.purchase">?</a></span><br><span>Geopolitik</span>: <span><a href="https://vuldb.com/?doc.purchase">?</a></span><br><span>Ökonomie</span>: <span><a href="https://vuldb.com/?doc.purchase">?</a></span><br><span>Voraussagen</span>: <span><a href="https://vuldb.com/?doc.purchase">?</a></span><br><span>Massnahmen</span>: <span><a href="https://vuldb.com/?doc.purchase">?</a></span><h2>Gegenmassnahmen</h2>
<span>Empfehlung</span>: keine Massnahme bekannt<br><span>0-Day Time</span>: <span><a href="https://vuldb.com/?login">?</a></span><h2>Timeline</h2>
<span>01.05.2018</span>  <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10592">CVE zugewiesen</a><br><span>31.07.2018</span>  Advisory veröffentlicht<br><span>01.08.2018</span>  <a href="https://vuldb.com/?id.122347">VulDB Eintrag erstellt</a><br><span>01.08.2018</span>  <a href="https://vuldb.com/?id.122347">VulDB letzte Aktualisierung</a><h2>Quellen</h2>
<span>CVE</span>: <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10592">CVE-2018-10592</a> (<span><a href="https://vuldb.com/?login">?</a></span>)<h2>Eintrag</h2>
<span>Erstellt</span>: 01.08.2018<br><span>Eintrag</span>: <span><a href="https://vuldb.com/?doc.purchase">?</a></span><br>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Hardcoded Credentials Expose Yokogawa Controllers to Attacks]]></title>
<description><![CDATA[Japanese electrical engineering company Yokogawa has released firmware updates for its STARDOM controllers to address a critical vulnerability that can be exploited remotely to take control of the device.
read more]]></description>
<link>https://tsecurity.de/de/321002/it-security-nachrichten/hardcoded-credentials-expose-yokogawa-controllers-to-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/321002/it-security-nachrichten/hardcoded-credentials-expose-yokogawa-controllers-to-attacks/</guid>
<pubDate>Fri, 01 Jun 2018 14:46:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<p><strong><span><span>Japanese electrical engineering company Yokogawa has released firmware updates for its STARDOM controllers to address a critical vulnerability that can be exploited remotely to take control of the device.</span></span></strong></p>
<p><a href="https://www.securityweek.com/hardcoded-credentials-expose-yokogawa-controllers-attacks" target="_blank">read more</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Securityweek?a=4Z1OndHMaXE:D7EOPZxtIuk:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Securityweek?d=yIl2AUoC8zA" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=4Z1OndHMaXE:D7EOPZxtIuk:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/Securityweek?i=4Z1OndHMaXE:D7EOPZxtIuk:-BTjWOF_DHI" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=4Z1OndHMaXE:D7EOPZxtIuk:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/Securityweek?d=dnMXMwOfBR0" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=4Z1OndHMaXE:D7EOPZxtIuk:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Securityweek?i=4Z1OndHMaXE:D7EOPZxtIuk:V_sGLiPBpWU" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=4Z1OndHMaXE:D7EOPZxtIuk:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Securityweek?d=qj6IDK7rITs" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=4Z1OndHMaXE:D7EOPZxtIuk:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Securityweek?i=4Z1OndHMaXE:D7EOPZxtIuk:gIN9vFwOqvQ" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=4Z1OndHMaXE:D7EOPZxtIuk:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/Securityweek?d=TzevzKxY174" border="0"></a> <a href="http://feeds.feedburner.com/~ff/Securityweek?a=4Z1OndHMaXE:D7EOPZxtIuk:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Securityweek?i=4Z1OndHMaXE:D7EOPZxtIuk:F7zBnMyn0Lo" border="0"></a>
</div>
<img src="http://feeds.feedburner.com/~r/Securityweek/~4/4Z1OndHMaXE" height="1" width="1" alt="">
]]></content:encoded>
</item>
<item>
<title><![CDATA[Sicherer und kompatibler: Yokogawa bringt ExaquantumTM R3.10 auf den Markt]]></title>
<description><![CDATA[Exaquantum R3.10 unterstützt die aktuellen Versionen aller gängigen Betriebssysteme, einschließlich Windows Server 2016, Windows 10 Enterprise 2016 LTSB und Microsoft SQL Server 2014. OLE for Process Control (OPC) ist der De-facto-Standard für Interoperabilität in der industriellen Automation ...]]></description>
<link>https://tsecurity.de/de/237838/windows-server/sicherer-und-kompatibler-yokogawa-bringt-exaquantumtm-r310-auf-den-markt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/237838/windows-server/sicherer-und-kompatibler-yokogawa-bringt-exaquantumtm-r310-auf-den-markt/</guid>
<pubDate>Wed, 06 Dec 2017 15:07:01 +0100</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Exaquantum R3.10 unterstützt die aktuellen Versionen aller gängigen Betriebssysteme, einschließlich <b>Windows Server</b> 2016, Windows 10 Enterprise 2016 LTSB und Microsoft SQL Server 2014. OLE for Process Control (OPC) ist der De-facto-Standard für Interoperabilität in der industriellen Automation ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa soll Sicherheit von BASF-Anlagen in Asien und Amerika verbessern]]></title>
<description><![CDATA[Yokogawa soll Sicherheit von BASF-Anlagen in Asien und Amerika ... umfangreiche Erfahrungen in internationalen Großprojekten der IT Security.]]></description>
<link>https://tsecurity.de/de/227226/it-security-nachrichten/yokogawa-soll-sicherheit-von-basf-anlagen-in-asien-und-amerika-verbessern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/227226/it-security-nachrichten/yokogawa-soll-sicherheit-von-basf-anlagen-in-asien-und-amerika-verbessern/</guid>
<pubDate>Fri, 10 Nov 2017 07:00:46 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Yokogawa soll Sicherheit von BASF-Anlagen in Asien und Amerika ... umfangreiche Erfahrungen in internationalen Großprojekten der <b>IT Security</b>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa führt Detailed Risk Assessments für die BASF in Asien und Amerika durch]]></title>
<description><![CDATA[... die geforderte Expertise in der Operational Technology als auch über umfangreiche Erfahrungen in internationalen Großprojekten der IT Security.]]></description>
<link>https://tsecurity.de/de/225347/it-security-nachrichten/yokogawa-fuehrt-detailed-risk-assessments-fuer-die-basf-in-asien-und-amerika-durch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/225347/it-security-nachrichten/yokogawa-fuehrt-detailed-risk-assessments-fuer-die-basf-in-asien-und-amerika-durch/</guid>
<pubDate>Mon, 06 Nov 2017 14:15:44 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... die geforderte Expertise in der Operational Technology als auch über umfangreiche Erfahrungen in internationalen Großprojekten der <b>IT Security</b>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa STARDOM FCN-FCJ bis R4.01 Logic Designer erweiterte Rechte]]></title>
<description><![CDATA[In Yokogawa STARDOM FCN-FCJ bis R4.01 wurde eine Schwachstelle gefunden. Sie wurde als kritisch eingestuft. Betroffen ist eine unbekannte Funktion der Komponente Logic Designer. Mit der Manipulation mit einer unbekannten Eingabe kann eine erweiterte Rechte-Schwachstelle ausgenutzt werden. Auswirk...]]></description>
<link>https://tsecurity.de/de/73828/sicherheitsluecken/yokogawa-stardom-fcn-fcj-bis-r401-logic-designer-erweiterte-rechte/</link>
<guid isPermaLink="true">https://tsecurity.de/de/73828/sicherheitsluecken/yokogawa-stardom-fcn-fcj-bis-r401-logic-designer-erweiterte-rechte/</guid>
<pubDate>Mon, 19 Sep 2016 09:31:02 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In Yokogawa STARDOM FCN-FCJ bis R4.01 wurde eine Schwachstelle gefunden. Sie wurde als kritisch eingestuft. Betroffen ist eine unbekannte Funktion der Komponente <em>Logic Designer</em>. Mit der Manipulation mit einer unbekannten Eingabe kann eine erweiterte Rechte-Schwachstelle ausgenutzt werden. Auswirken tut sich dies auf Vertraulichkeit, Integrität und Verfügbarkeit. </p><p>Die Schwachstelle wurde am 19.09.2016 öffentlich gemacht. Die Verwundbarkeit wird als <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4860">CVE-2016-4860</a> geführt. Der Angriff kann über das Netzwerk angegangen werden. Um eine Ausnutzung durchzusetzen, muss keine spezifische Authentisierung umgesetzt werden. Technische Details sind nicht bekannt und ein Exploit zur Schwachstelle ist ebenfalls nicht vorhanden. Die Beschaffenheit der Schwachstelle lässt vermuten, dass ein Exploit momentan zu etwa USD $2k-$5k gehandelt werden wird. </p><p></p><p>Es sind keine Informationen bezüglich Gegenmassnahmen bekannt. Der Einsatz eines alternativen Produkts bietet sich im Zweifelsfall an.</p><p></p><h2>CVSSv3</h2><span>Base Score</span>: 7.3 <a href="https://www.first.org/cvss/specification-document#i2">[?]</a><br><span>Temp Score</span>: 7.3 <a href="https://www.first.org/cvss/specification-document#i3">[?]</a><br><span>Vector</span>: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:X <a href="https://www.first.org/cvss/specification-document#i6">[?]</a><br><span>Zuverlässigkeit</span>: Medium<br><h2>CVSSv2</h2><span>Base Score</span>: 6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P) <a href="https://www.first.org/cvss/v2/guide#i2.1">[?]</a><br><span>Temp Score</span>: 6.8 (CVSS2#E:ND/RL:ND/RC:ND) <a href="https://www.first.org/cvss/v2/guide#i2.2">[?]</a><br><span>Zuverlässigkeit</span>: Medium<br><h2>CPE</h2><ul><li><a href="https://web.nvd.nist.gov/view/vuln/search-results?cpe=cpe%3A%2Fa%3Ayokogawa%3Astardom_fcn-fcj%3Ar4.01&amp;page_num=0&amp;cid=3">cpe:/a:yokogawa:stardom_fcn-fcj:r4.01</a></li></ul><h2>Exploiting</h2><span>Klasse</span>: Erweiterte Rechte<br><span>Lokal</span>: Nein<br><span>Remote</span>: Ja<br><br><span>Verfügbarkeit</span>: Nein<br><br><span>Aktuelle Preisschätzung</span>: <span>$0-$1k (0-day) / $0-$1k (Heute)</span><br><h2>Gegenmassnahmen</h2><span>Empfehlung</span>: keine Massnahme bekannt<br><span>0-Day Time</span>: 0 Tage seit gefunden<br><h2>Timeline</h2><span>19.09.2016</span>  Advisory veröffentlicht<br><span>19.09.2016</span>  <a href="https://vuldb.com///vuldb.com/?id.91687">VulDB Eintrag erstellt</a><br><span>19.09.2016</span>  <a href="https://vuldb.com///vuldb.com/?id.91687">VulDB letzte Aktualisierung</a><br><h2>Quellen</h2><br><span>CVE</span>: CVE-2016-4860 <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4860">(mitre.org)</a> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-4860">(nvd.nist.org)</a> <a href="http://www.cvedetails.com/cve/CVE-2016-4860/">(cvedetails.com)</a><br><h2>Eintrag</h2><span>Erstellt</span>: 19.09.2016<br><span>Eintrag</span>: 70.2% komplett<br>]]></content:encoded>
</item>
<item>
<title><![CDATA[Yokogawa STARDOM FCN-FCJ bis R4.01 Logic Designer erweiterte Rechte]]></title>
<description><![CDATA[In Yokogawa STARDOM FCN-FCJ bis R4.01 wurde eine Schwachstelle gefunden. Sie wurde als kritisch eingestuft. Betroffen ist eine unbekannte Funktion der Komponente Logic Designer. Mit der Manipulation mit einer unbekannten Eingabe kann eine erweiterte Rechte-Schwachstelle ausgenutzt werden. Auswirk...]]></description>
<link>https://tsecurity.de/de/73828/sicherheitsluecken/yokogawa-stardom-fcn-fcj-bis-r401-logic-designer-erweiterte-rechte/</link>
<guid isPermaLink="true">https://tsecurity.de/de/73828/sicherheitsluecken/yokogawa-stardom-fcn-fcj-bis-r401-logic-designer-erweiterte-rechte/</guid>
<pubDate>Mon, 19 Sep 2016 09:31:02 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In Yokogawa STARDOM FCN-FCJ bis R4.01 wurde eine Schwachstelle gefunden. Sie wurde als kritisch eingestuft. Betroffen ist eine unbekannte Funktion der Komponente <em>Logic Designer</em>. Mit der Manipulation mit einer unbekannten Eingabe kann eine erweiterte Rechte-Schwachstelle ausgenutzt werden. Auswirken tut sich dies auf Vertraulichkeit, Integrität und Verfügbarkeit. </p><p>Die Schwachstelle wurde am 19.09.2016 öffentlich gemacht. Die Verwundbarkeit wird als <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4860">CVE-2016-4860</a> geführt. Der Angriff kann über das Netzwerk angegangen werden. Um eine Ausnutzung durchzusetzen, muss keine spezifische Authentisierung umgesetzt werden. Technische Details sind nicht bekannt und ein Exploit zur Schwachstelle ist ebenfalls nicht vorhanden. Die Beschaffenheit der Schwachstelle lässt vermuten, dass ein Exploit momentan zu etwa USD $2k-$5k gehandelt werden wird. </p><p></p><p>Es sind keine Informationen bezüglich Gegenmassnahmen bekannt. Der Einsatz eines alternativen Produkts bietet sich im Zweifelsfall an.</p><p></p><h2>CVSSv3</h2><span>Base Score</span>: 7.3 <a href="https://www.first.org/cvss/specification-document#i2">[?]</a><br><span>Temp Score</span>: 7.3 <a href="https://www.first.org/cvss/specification-document#i3">[?]</a><br><span>Vector</span>: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:X <a href="https://www.first.org/cvss/specification-document#i6">[?]</a><br><span>Zuverlässigkeit</span>: Medium<br><h2>CVSSv2</h2><span>Base Score</span>: 6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P) <a href="https://www.first.org/cvss/v2/guide#i2.1">[?]</a><br><span>Temp Score</span>: 6.8 (CVSS2#E:ND/RL:ND/RC:ND) <a href="https://www.first.org/cvss/v2/guide#i2.2">[?]</a><br><span>Zuverlässigkeit</span>: Medium<br><h2>CPE</h2><ul><li><a href="https://web.nvd.nist.gov/view/vuln/search-results?cpe=cpe%3A%2Fa%3Ayokogawa%3Astardom_fcn-fcj%3Ar4.01&amp;page_num=0&amp;cid=3">cpe:/a:yokogawa:stardom_fcn-fcj:r4.01</a></li></ul><h2>Exploiting</h2><span>Klasse</span>: Erweiterte Rechte<br><span>Lokal</span>: Nein<br><span>Remote</span>: Ja<br><br><span>Verfügbarkeit</span>: Nein<br><br><span>Aktuelle Preisschätzung</span>: <span>$0-$1k (0-day) / $0-$1k (Heute)</span><br><h2>Gegenmassnahmen</h2><span>Empfehlung</span>: keine Massnahme bekannt<br><span>0-Day Time</span>: 0 Tage seit gefunden<br><h2>Timeline</h2><span>19.09.2016</span>  Advisory veröffentlicht<br><span>19.09.2016</span>  <a href="https://vuldb.com///vuldb.com/?id.91687">VulDB Eintrag erstellt</a><br><span>19.09.2016</span>  <a href="https://vuldb.com///vuldb.com/?id.91687">VulDB letzte Aktualisierung</a><br><h2>Quellen</h2><br><span>CVE</span>: CVE-2016-4860 <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4860">(mitre.org)</a> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-4860">(nvd.nist.org)</a> <a href="http://www.cvedetails.com/cve/CVE-2016-4860/">(cvedetails.com)</a><br><h2>Eintrag</h2><span>Erstellt</span>: 19.09.2016<br><span>Eintrag</span>: 70.2% komplett<br>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,05ms -->