PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-66603 Yokogawa CVE debrief

CVE-2025-66603 is a low-severity issue in Yokogawa FAST/TOOLS where the web server accepts the HTTP OPTIONS method. The advisory says this information could potentially be used to carry out other attacks, so the main concern is reconnaissance and chaining rather than direct impact. Yokogawa’s remediation is to update to R10.04, apply patch software CS_e12787, and then apply R10.04 SP3.

Vendor
Yokogawa
Product
FAST/TOOLS
CVSS
LOW 3.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-02-10
Original CVE updated
2026-02-10
Advisory published
2026-02-10
Advisory updated
2026-02-10

Who should care

Operators and administrators of Yokogawa FAST/TOOLS deployments, especially OT/ICS teams that expose the product’s web server internally or externally. Security teams responsible for segmentation, patching, and routine hardening in industrial environments should also review it.

Technical summary

CISA’s CSAF advisory for ICSA-26-041-01 describes a FAST/TOOLS web server that accepts OPTIONS requests. The supplied CVSS 3.1 vector is AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N, which aligns with limited confidentiality impact, no integrity or availability impact, and a requirement for user interaction. The issue is best understood as a low-impact information disclosure / capability-enumeration weakness that may help an attacker prepare or chain follow-on activity. The published remediation sequence is to update to R10.04, apply patch software CS_e12787, and then apply R10.04 SP3.

Defensive priority

Low overall, but worth addressing in the next planned maintenance window if FAST/TOOLS is in use, reachable on a network, or part of a sensitive OT environment.

Recommended defensive actions

  • Update Yokogawa FAST/TOOLS to revision R10.04.
  • Apply patch software CS_e12787, then apply R10.04 SP3 as directed by the advisory.
  • Review how the FAST/TOOLS web server is exposed and restrict access using segmentation and firewall controls where appropriate.
  • Follow Yokogawa and CISA ICS defense-in-depth guidance, including hardening, whitelisting, backup/recovery, and routine security program maintenance.

Evidence notes

This debrief is based on the supplied CISA CSAF advisory metadata and remediation text for ICSA-26-041-01. The source description states that the web server accepts the OPTIONS method and that an attacker could potentially use that information to carry out other attacks. The advisory metadata includes the CVSS 3.1 vector AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N and a revision history noting an initial republication of YSAR-26-0001-E on 2026-02-10. No KEV entry was provided in the source corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-66603 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-66603

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-66603 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-66603

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-041-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-041-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.