PatchSiren cyber security CVE debrief
CVE-2025-66603 Yokogawa CVE debrief
CVE-2025-66603 is a low-severity issue in Yokogawa FAST/TOOLS where the web server accepts the HTTP OPTIONS method. The advisory says this information could potentially be used to carry out other attacks, so the main concern is reconnaissance and chaining rather than direct impact. Yokogawa’s remediation is to update to R10.04, apply patch software CS_e12787, and then apply R10.04 SP3.
- Vendor
- Yokogawa
- Product
- FAST/TOOLS
- CVSS
- LOW 3.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-10
- Original CVE updated
- 2026-02-10
- Advisory published
- 2026-02-10
- Advisory updated
- 2026-02-10
Who should care
Operators and administrators of Yokogawa FAST/TOOLS deployments, especially OT/ICS teams that expose the product’s web server internally or externally. Security teams responsible for segmentation, patching, and routine hardening in industrial environments should also review it.
Technical summary
CISA’s CSAF advisory for ICSA-26-041-01 describes a FAST/TOOLS web server that accepts OPTIONS requests. The supplied CVSS 3.1 vector is AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N, which aligns with limited confidentiality impact, no integrity or availability impact, and a requirement for user interaction. The issue is best understood as a low-impact information disclosure / capability-enumeration weakness that may help an attacker prepare or chain follow-on activity. The published remediation sequence is to update to R10.04, apply patch software CS_e12787, and then apply R10.04 SP3.
Defensive priority
Low overall, but worth addressing in the next planned maintenance window if FAST/TOOLS is in use, reachable on a network, or part of a sensitive OT environment.
Recommended defensive actions
- Update Yokogawa FAST/TOOLS to revision R10.04.
- Apply patch software CS_e12787, then apply R10.04 SP3 as directed by the advisory.
- Review how the FAST/TOOLS web server is exposed and restrict access using segmentation and firewall controls where appropriate.
- Follow Yokogawa and CISA ICS defense-in-depth guidance, including hardening, whitelisting, backup/recovery, and routine security program maintenance.
Evidence notes
This debrief is based on the supplied CISA CSAF advisory metadata and remediation text for ICSA-26-041-01. The source description states that the web server accepts the OPTIONS method and that an attacker could potentially use that information to carry out other attacks. The advisory metadata includes the CVSS 3.1 vector AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N and a revision history noting an initial republication of YSAR-26-0001-E on 2026-02-10. No KEV entry was provided in the source corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-66603 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-66603
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-66603 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-66603
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-041-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-041-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.