PatchSiren cyber security CVE debrief
CVE-2025-48020 Yokogawa Electric Corporation CVE debrief
CVE-2025-48020 affects Yokogawa CENTUM VP R6 and R7 Vnet/IP Interface Package versions up to R1.07.00. According to the advisory, maliciously crafted packets can terminate the Vnet/IP software stack process, creating an availability impact for affected OT environments. Yokogawa recommends upgrading to R1.08.00.
- Vendor
- Yokogawa Electric Corporation
- Product
- Yokogawa Vnet/IP Interface Package for CENTUM VP R6 (VP6C3300) <=R1.07.00 Vnet/IP Interface Package for CENTUM VP R7 (VP7C3300)
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-26
- Original CVE updated
- 2026-02-26
- Advisory published
- 2026-02-26
- Advisory updated
- 2026-02-26
Who should care
OT operators, industrial network administrators, system integrators, and asset owners running Yokogawa CENTUM VP R6/R7 with the affected Vnet/IP Interface Package (VP6C3300 or VP7C3300) should review exposure and remediation plans.
Technical summary
The advisory describes a packet-handling issue in the Vnet/IP software stack: if the affected product receives maliciously crafted packets, the process may terminate. The supplied CVSS vector indicates an adjacent-network attack path, high attack complexity, no privileges, no user interaction, and an availability-only impact (CVSS 3.1 5.3/Medium). The remediation provided by the vendor is to apply patch software R1.08.00.
Defensive priority
Medium priority for exposed OT networks. The issue is availability-focused and requires adjacency to the target network, but process termination in industrial communications infrastructure can still disrupt operations.
Recommended defensive actions
- Upgrade affected systems to Yokogawa patch software R1.08.00 as recommended in the advisory.
- Identify whether VP6C3300 or VP7C3300 installations are running versions at or below R1.07.00.
- Restrict adjacent-network access to the Vnet/IP segment and limit packet sources to trusted OT hosts and management systems.
- Monitor the Vnet/IP stack and related logs for unexpected process terminations or abnormal packet patterns.
- Review the Yokogawa advisory YSAR-26-0002 for implementation guidance and contact the local supporting office if remediation planning is needed.
Evidence notes
The source advisory states: "If the affected product receives maliciously crafted packets, Vnet/IP software stack process may be terminated." It also recommends applying patch software R1.08.00. The CVSS vector in the supplied record is CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H, which aligns with an adjacent-network, availability-only issue. Published and modified dates supplied for the CVE and source are 2026-02-26T07:00:00.000Z.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-48020 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-48020
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-48020 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-48020
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-057-09.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-09
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.