PatchSiren cyber security CVE debrief
CVE-2025-66607 Yokogawa CVE debrief
CVE-2025-66607 affects Yokogawa FAST/TOOLS and is described by CISA as an insecure response-header setting that could let an attacker redirect users to malicious sites. The supplied CVSS 3.1 vector rates it low severity with network access and higher attack conditions required, and only integrity impact indicated. Yokogawa’s remediation guidance is to update to R10.04, apply patch software CS_e12787, and then apply R10.04 SP3.
- Vendor
- Yokogawa
- Product
- FAST/TOOLS
- CVSS
- LOW 3.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-10
- Original CVE updated
- 2026-02-10
- Advisory published
- 2026-02-10
- Advisory updated
- 2026-02-10
Who should care
OT and ICS administrators, Yokogawa FAST/TOOLS operators, SCADA platform owners, and security teams responsible for user access to FAST/TOOLS environments.
Technical summary
The advisory describes a response-header configuration weakness in FAST/TOOLS. Based on the supplied CVSS vector (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N), exploitation is network-reachable but not simple, with no privilege requirements and no user interaction required in the score, and the primary impact is limited to integrity. The record does not indicate confidentiality or availability impact.
Defensive priority
Low to moderate. The score is low, but the issue can affect user trust and route users toward malicious destinations, so it should be handled in routine OT patching and configuration review.
Recommended defensive actions
- Update Yokogawa FAST/TOOLS to revision R10.04.
- Apply Yokogawa patch software CS_e12787.
- After patching, move to R10.04 SP3 as recommended by Yokogawa.
- Review FAST/TOOLS response-header behavior and related redirect handling during validation.
- Follow CISA ICS recommended practices for patching, hardening, zoning, and defense-in-depth around OT systems.
Evidence notes
This debrief is based on the supplied CISA CSAF advisory ICSA-26-041-01 and its remediation text. The record provided no KEV listing and no ransomware-campaign association. Timing follows the supplied published and modified dates of 2026-02-10.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-66607 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-66607
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-66607 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-66607
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-041-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-041-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.