PatchSiren cyber security CVE debrief
CVE-2025-7741 Yokogawa Electric Corporation CVE debrief
CVE-2025-7741 affects Yokogawa CENTUM VP and involves a hardcoded password for the PROG account used in CENTUM Authentication Mode. The advisory says an attacker may be able to log in as PROG, but exploitation already requires access to the HIS screen controls. By default, PROG has S1 permission (equivalent to OFFUSER), which reduces the likelihood of critical operations or configuration changes. Risk increases if PROG permissions were changed from the default.
- Vendor
- Yokogawa Electric Corporation
- Product
- Yokogawa CENTUM VP >=R5.01.00|<R5.04.20 >=R6.01.00|<R6.12.00 vR7.01.00
- CVSS
- MEDIUM 4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-02
- Original CVE updated
- 2026-04-02
- Advisory published
- 2026-04-02
- Advisory updated
- 2026-04-02
Who should care
OT/ICS administrators, control-room engineers, and incident responders running Yokogawa CENTUM VP, especially sites using CENTUM Authentication Mode, exposed HIS screen controls, or customized PROG permissions.
Technical summary
The issue is a hardcoded password affecting the PROG user account in CENTUM Authentication Mode. CISA's advisory states that the default PROG permission is S1, equivalent to OFFUSER, so impact is generally limited when permissions remain unchanged. If PROG permissions have been modified, successful login as PROG could permit operations or configuration changes under those elevated rights. The advisory also notes that an attacker must already have access to the HIS screen controls, which constrains exposure.
Defensive priority
Medium: prioritize remediation for affected CENTUM VP systems that use CENTUM Authentication Mode, have accessible HIS screen controls, or have any non-default PROG permissions.
Recommended defensive actions
- For CENTUM VP R5.01.00 through <R5.04.20 and R6.01.00 through <R6.12.00, change the user authentication mode to Windows Authentication Mode per Yokogawa guidance.
- For CENTUM VP R7.01.00, apply patch software R7.01.10.
- Review PROG account permissions and restore the default S1 permission model if it has been changed.
- Restrict and monitor access to HIS screen controls and other operator-facing interfaces to reduce the chance of unauthorized PROG login attempts.
- Follow Yokogawa advisory YSAR-26-0003 and validate the remediation in an engineering/test environment before deploying to production.
Evidence notes
The supplied CISA CSAF advisory for ICSA-26-092-02 states that affected Yokogawa CENTUM VP products contain a hardcoded password for the PROG user account used in CENTUM Authentication Mode. It also states that exploitation requires prior access to HIS screen controls. The advisory further explains that PROG defaults to S1 permission (equivalent to OFFUSER), which lowers the practical impact unless permissions were changed. Remediations in the source corpus include switching affected R5/R6 systems to Windows Authentication Mode and applying R7.01.10 for R7.01.00.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-7741 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-7741
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-7741 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-7741
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-092-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.