PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-4105 Yokogawa CVE debrief

A reflected cross-site scripting (XSS) vulnerability in Yokogawa FAST/TOOLS and CI Server WEB HMI components allows malicious script execution when client PCs access crafted URLs. Published 2024-06-27.

Vendor
Yokogawa
Product
FAST/TOOLS RVSVRN Package
CVSS
MEDIUM 5.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-06-27
Original CVE updated
2024-06-27
Advisory published
2024-06-27
Advisory updated
2024-06-27

Who should care

Organizations operating Yokogawa FAST/TOOLS (versions R9.01–R10.04) or CI Server (versions R1.01.00–R1.03.00) in industrial environments, particularly those with externally accessible or poorly segmented WEB HMI interfaces. Critical infrastructure operators in energy, manufacturing, and process industries using these SCADA/HMI platforms should prioritize patching and access controls.

Technical summary

The WEB HMI server in affected Yokogawa products improperly processes HTTP requests, enabling reflected XSS attacks. An attacker can craft a malicious URL containing script payloads; when a client PC with inadequate security measures accesses this URL, the script executes in the browser context. This requires user interaction (accessing the crafted URL) but can compromise client sessions or enable further attacks against HMI infrastructure.

Defensive priority

MEDIUM

Recommended defensive actions

  • Apply vendor patches: For FAST/TOOLS, update to R10.04, apply patch R10.04 SP3, then apply patch I12560. For CI Server, update to R1.03.00 and apply patch R10.04 SP3.
  • Change default account passwords if not already modified, per patch documentation.
  • Implement defense-in-depth security controls including network segmentation, host hardening, application whitelisting, and firewall restrictions for WEB HMI access.
  • Contact Yokogawa for security risk assessment services to establish comprehensive security program covering patch management, anti-virus, backup/recovery, and zoning.
  • Restrict WEB HMI access to trusted networks and enforce client-side security measures on systems accessing HMI interfaces.

Evidence notes

Source: CISA CSAF advisory ICSA-24-179-03 (2024-06-27). CVSS 3.1 score 5.8 (MEDIUM). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N. Not listed in CISA KEV.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-4105 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-4105

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-4105 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-4105

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-179-03.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-179-03

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.