PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-1924 Yokogawa Electric Corporation CVE debrief

CVE-2025-1924 is an OT advisory for Yokogawa CENTUM VP environments using the Vnet/IP Interface Package. According to CISA’s CSAF advisory, maliciously crafted packets can cause a denial of service that stops Vnet/IP communication functions, and the advisory also warns that arbitrary programs may be executed. Yokogawa’s recommended fix is patch software R1.08.00.

Vendor
Yokogawa Electric Corporation
Product
Yokogawa Vnet/IP Interface Package for CENTUM VP R6 (VP6C3300) <=R1.07.00 Vnet/IP Interface Package for CENTUM VP R7 (VP7C3300)
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-02-26
Original CVE updated
2026-02-26
Advisory published
2026-02-26
Advisory updated
2026-02-26

Who should care

Industrial control system operators, OT engineers, and site administrators running Yokogawa CENTUM VP R6 or R7 with the Vnet/IP Interface Package should review this advisory, especially if the interface package is reachable from adjacent network segments.

Technical summary

The supplied advisory describes a packet-handling flaw in the Vnet/IP Interface Package for CENTUM VP. If the affected product receives maliciously crafted packets, the result may be a denial of service affecting Vnet/IP communication functions; the advisory also states arbitrary programs may be executed. The published CVSS vector (AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H) indicates an adjacent-network attack with high availability impact and some integrity impact.

Defensive priority

High for OT networks where Vnet/IP communication availability is operationally critical. Even with an AC:H rating, disruption of communication functions can affect process monitoring and control, so patching and segmentation should be prioritized.

Recommended defensive actions

  • Apply Yokogawa patch software R1.08.00 as recommended in the advisory.
  • Confirm whether your environment uses the affected CENTUM VP R6 or R7 Vnet/IP Interface Package builds.
  • Restrict adjacent-network access to the affected OT segment and reduce exposure of Vnet/IP communication paths.
  • Monitor for unexpected crashes, communication interruptions, or abnormal packet-related instability on affected systems.
  • Contact a local Yokogawa supporting office and follow the vendor advisory YSAR-26-0002 for implementation guidance.

Evidence notes

This debrief is based on the supplied CISA CSAF source for ICSA-26-057-09 (republishing YSAR-26-0002) and the accompanying official links. The source states that maliciously crafted packets can stop Vnet/IP communication functions or allow arbitrary programs to be executed, and that patch software R1.08.00 is the vendor-recommended mitigation. No KEV listing was provided in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-1924 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-1924

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-1924 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-1924

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-057-09.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-09

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.