PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-48020 Yokogawa Electric Corporation CVE debrief

CVE-2025-48020 affects Yokogawa CENTUM VP R6 and R7 Vnet/IP Interface Package versions up to R1.07.00. According to the advisory, maliciously crafted packets can terminate the Vnet/IP software stack process, creating an availability impact for affected OT environments. Yokogawa recommends upgrading to R1.08.00.

Vendor
Yokogawa Electric Corporation
Product
Yokogawa Vnet/IP Interface Package for CENTUM VP R6 (VP6C3300) <=R1.07.00 Vnet/IP Interface Package for CENTUM VP R7 (VP7C3300)
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-02-26
Original CVE updated
2026-02-26
Advisory published
2026-02-26
Advisory updated
2026-02-26

Who should care

OT operators, industrial network administrators, system integrators, and asset owners running Yokogawa CENTUM VP R6/R7 with the affected Vnet/IP Interface Package (VP6C3300 or VP7C3300) should review exposure and remediation plans.

Technical summary

The advisory describes a packet-handling issue in the Vnet/IP software stack: if the affected product receives maliciously crafted packets, the process may terminate. The supplied CVSS vector indicates an adjacent-network attack path, high attack complexity, no privileges, no user interaction, and an availability-only impact (CVSS 3.1 5.3/Medium). The remediation provided by the vendor is to apply patch software R1.08.00.

Defensive priority

Medium priority for exposed OT networks. The issue is availability-focused and requires adjacency to the target network, but process termination in industrial communications infrastructure can still disrupt operations.

Recommended defensive actions

  • Upgrade affected systems to Yokogawa patch software R1.08.00 as recommended in the advisory.
  • Identify whether VP6C3300 or VP7C3300 installations are running versions at or below R1.07.00.
  • Restrict adjacent-network access to the Vnet/IP segment and limit packet sources to trusted OT hosts and management systems.
  • Monitor the Vnet/IP stack and related logs for unexpected process terminations or abnormal packet patterns.
  • Review the Yokogawa advisory YSAR-26-0002 for implementation guidance and contact the local supporting office if remediation planning is needed.

Evidence notes

The source advisory states: "If the affected product receives maliciously crafted packets, Vnet/IP software stack process may be terminated." It also recommends applying patch software R1.08.00. The CVSS vector in the supplied record is CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H, which aligns with an adjacent-network, availability-only issue. Published and modified dates supplied for the CVE and source are 2026-02-26T07:00:00.000Z.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-48020 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-48020

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-48020 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-48020

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-057-09.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-09

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.