IM
IronMonkey Threat Research
‹ Back to ICS Advisories

YSAR-24-0001: Vulnerabilities in FAST/TOOLS and CI Server

MEDIUM
CVSS 5.8
Date 2026-07-28T15:24:09+00:00
Source yokogawa
Published by Yokogawa

// Description

1 / 2YSAR-24-0001-E Yokogawa Security Advisory Report > All Rights Reserved. Copyright © 2024, Yokogawa Electric Corporation # Yokogawa Security Advisory Report # YSAR-24-0001 Published on June 26, 2024 Last updated on July 4, 2024 ## YSAR-24-0001: Vulnerabilities in FAST/TOOLS and CI Server Overview: Vulnerabilities has been found in FAST/TOOLS and CI Server. Yokogawa has identified the range of affected products in this report. Please review the report and confirm which prod

// Vulnerabilities (2)

CVE ID CVSS Score Severity Description
CVE-2024-4106 5.8 medium
The affected products have built-in accounts with no passwords set. Therefore, if the product is operated without a password set by default, an attacker can break into the affected product.
CVE-2024-4105 5.8 medium
The affected product's WEB HMI server's function to process HTTP requests has a security flaw (reflected XSS) that allows the execution of malicious scripts. Therefore, if a client PC with inadequate security measures accesses a product URL containing a malicious request, the malicious script may be executed on the client PC.

// Affected Products (2)

Vendor Product Asset Type Purdue Level Firmware
Yokogawa Unknown hmi
L2
--
Yokogawa Unknown hmi
L2
--

// Remediations (5)

Patch: Yokogawa recommends customers using Collaborative Information Server (CI Server) to update to R1.03.
Yokogawa recommends customers using Collaborative Information Server (CI Server) to update to R1.03.00 and apply patch software R10.04 SP3.
Mitigation: Yokogawa recommends customers using FAST/TOOLS to update to R10.04 and first apply patch software R1
Yokogawa recommends customers using FAST/TOOLS to update to R10.04 and first apply patch software R10.04 SP3 and afterwards apply patch software I12560.
Mitigation: For questions related to this report, please contact Yokogawa
For questions related to this report, please contact Yokogawa
Mitigation: For both platforms, if the password for the default account has not been changed, please change that
For both platforms, if the password for the default account has not been changed, please change that password according to the documentation included with the patch software.
Mitigation: Yokogawa strongly recommends all customers to establish and maintain a full security program, not on
Yokogawa strongly recommends all customers to establish and maintain a full security program, not only for the vulnerability identified in this YSAR. Security program components are: Patch updates, Anti-virus, Backup and recovery, zoning, hardening, whitelisting, firewall, etc. Yokogawa can assist in setting up and running the security program continuously. For considering the most effective risk mitigation plan, as a starting point, Yokogawa can perform a security risk assessment.

// References