PatchSiren cyber security CVE debrief
CVE-2025-48022 Yokogawa Electric Corporation CVE debrief
CVE-2025-48022 affects Yokogawa CENTUM VP R6 and R7 systems using the Vnet/IP Interface Package at versions up to R1.07.00. According to CISA’s advisory, maliciously crafted packets can terminate the Vnet/IP software stack process, creating an availability impact in an OT/ICS environment. The advisory was published on 2026-02-26 and maps to CVSS 3.1 5.3 (Medium).
- Vendor
- Yokogawa Electric Corporation
- Product
- Yokogawa Vnet/IP Interface Package for CENTUM VP R6 (VP6C3300) <=R1.07.00 Vnet/IP Interface Package for CENTUM VP R7 (VP7C3300)
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-26
- Original CVE updated
- 2026-02-26
- Advisory published
- 2026-02-26
- Advisory updated
- 2026-02-26
Who should care
OT/ICS operators, plant engineers, and security teams responsible for Yokogawa CENTUM VP deployments that use the affected Vnet/IP Interface Package versions, especially where availability of control communications is operationally critical.
Technical summary
The supplied CISA CSAF advisory states that if the affected product receives maliciously crafted packets, the Vnet/IP software stack process may be terminated. The published CVSS vector is AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating an adjacent-network, high-complexity condition with no privileges or user interaction required and impact limited to availability. The remediation guidance in the advisory recommends upgrading to patch software R1.08.00.
Defensive priority
Medium. The CVSS score is moderate, but the operational impact can be significant in industrial environments because a terminated Vnet/IP stack process may disrupt control communications or availability.
Recommended defensive actions
- Apply Yokogawa patch software R1.08.00 for the affected Vnet/IP Interface Package versions.
- Contact Yokogawa or the local supporting office for product-specific guidance and deployment support.
- Review Yokogawa advisory YSAR-26-0002 for implementation details and mitigation guidance.
- Limit exposure of affected OT assets to trusted adjacent-network segments and follow CISA ICS recommended practices for defense in depth.
- Monitor affected systems for unexpected Vnet/IP stack process termination or related availability anomalies.
Evidence notes
All claims above are based on the supplied CISA CSAF advisory for ICSA-26-057-09 / CVE-2025-48022. The source text explicitly says maliciously crafted packets may terminate the Vnet/IP software stack process and lists the patch recommendation of R1.08.00. The advisory metadata provided in the corpus includes the 2026-02-26 publication/modified date and the CVSS 3.1 vector AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H. No KEV entry is present in the supplied data.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-48022 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-48022
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-48022 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-48022
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-057-09.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-09
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.