PatchSiren cyber security CVE debrief
CVE-2024-4105 Yokogawa CVE debrief
A reflected cross-site scripting (XSS) vulnerability in Yokogawa FAST/TOOLS and CI Server WEB HMI components allows malicious script execution when client PCs access crafted URLs. Published 2024-06-27.
- Vendor
- Yokogawa
- Product
- FAST/TOOLS RVSVRN Package
- CVSS
- MEDIUM 5.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-06-27
- Original CVE updated
- 2024-06-27
- Advisory published
- 2024-06-27
- Advisory updated
- 2024-06-27
Who should care
Organizations operating Yokogawa FAST/TOOLS (versions R9.01–R10.04) or CI Server (versions R1.01.00–R1.03.00) in industrial environments, particularly those with externally accessible or poorly segmented WEB HMI interfaces. Critical infrastructure operators in energy, manufacturing, and process industries using these SCADA/HMI platforms should prioritize patching and access controls.
Technical summary
The WEB HMI server in affected Yokogawa products improperly processes HTTP requests, enabling reflected XSS attacks. An attacker can craft a malicious URL containing script payloads; when a client PC with inadequate security measures accesses this URL, the script executes in the browser context. This requires user interaction (accessing the crafted URL) but can compromise client sessions or enable further attacks against HMI infrastructure.
Defensive priority
MEDIUM
Recommended defensive actions
- Apply vendor patches: For FAST/TOOLS, update to R10.04, apply patch R10.04 SP3, then apply patch I12560. For CI Server, update to R1.03.00 and apply patch R10.04 SP3.
- Change default account passwords if not already modified, per patch documentation.
- Implement defense-in-depth security controls including network segmentation, host hardening, application whitelisting, and firewall restrictions for WEB HMI access.
- Contact Yokogawa for security risk assessment services to establish comprehensive security program covering patch management, anti-virus, backup/recovery, and zoning.
- Restrict WEB HMI access to trusted networks and enforce client-side security measures on systems accessing HMI interfaces.
Evidence notes
Source: CISA CSAF advisory ICSA-24-179-03 (2024-06-27). CVSS 3.1 score 5.8 (MEDIUM). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N. Not listed in CISA KEV.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-4105 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-4105
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-4105 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-4105
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-179-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-179-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.