IM
IronMonkey Threat Research
‹ Back to ICS Advisories

YSAR-26-0003: Hardcoded Password Vulnerability in CENTUM

MEDIUM
CVSS 4.0
Date 2026-07-28T15:23:50+00:00
Source yokogawa
Published by Yokogawa

// Description

1 / 2YSAR-26-0003-E Yokogawa Security Advisory Report > All Rights Reserved. Copyright © 2026, Yokogawa Electric Corporation # Yokogawa Security Advisory Report # YSAR-26-0003 Published on March 27, 2026 Last updated on March 27, 2026 ## YSAR-26-0003: Hardcoded Password Vulnerability in CENTUM Overview: Hardcoded Password Vulnerability have been found in CENTUM. Yokogawa has identified the range of affected products in this report. Please review the report and confirm which pr

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2025-7741 4.0 critical
Affected products contain a hardcoded password for the user account (PROG) used for CENTUM Authentication Mode within the system. Under the following conditions, there is a risk that an attacker could log in as the PROG user. The default permission for the PROG users is S1 permission (equivalent to OFFUSER). Therefore, for properly permission-controlled targets of operation and monitoring, even if an attacker logs in as the PROG user, the risk of critical operations or configuration changes being performed is considered low. If the PROG user's permissions have been changed for any reason, there is a risk that operations or configuration changes may be performed under the modified permissions. Additionally, exploiting this vulnerability requires an attacker to already have access to the HIS screen controls.

// Affected Products (1)

Vendor Product Asset Type Purdue Level Firmware
Yokogawa Unknown dcs
L2
--

// Remediations (6)

Patch: CENTUM VP R5.01.00 to R5.04.20: Change the user authentication mode to Windows Authentication Mode.
CENTUM VP R5.01.00 to R5.04.20: Change the user authentication mode to Windows Authentication Mode.
Patch: CENTUM VP R6.01.00 to R6.12.00: Change the user authentication mode to Windows Authentication Mode.
CENTUM VP R6.01.00 to R6.12.00: Change the user authentication mode to Windows Authentication Mode.
Mitigation: NOTE:Changing to Windows Authentication Mode requires engineering work. If users wish to make this c
NOTE:Changing to Windows Authentication Mode requires engineering work. If users wish to make this change, please contact Yokogawa directly https://contact.yokogawa.com/cs/gw?c-id=000498.
Mitigation: Yokogawa recommends users applying the following mitigations to affected versions:
Yokogawa recommends users applying the following mitigations to affected versions:
Patch: CENTUM VP R7.01.00: Apply patch software R7.01.10.
CENTUM VP R7.01.00: Apply patch software R7.01.10.
Mitigation: For more information and details on implementing these mitigations, users should see the Yokogawa ad
For more information and details on implementing these mitigations, users should see the Yokogawa advisory YSAR-26-0003 at https://web-material3.yokogawa.com/1/39281/files/YSAR-26-0003-E.pdf

// References