High7.1
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

PT-2026-12: OOB memory read in a handler of the command in Yokogawa Centum VP

Error type:

  • CWE-191:Integer Underflow (Wrap or Wraparound)

Vulnerability vector:

  • Base vulnerability score (CVSSv4.0): CVSS:4.0/ AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

  • Severity (CVSSv4.0): 7.1 (High)

Description:

The vulnerability was identified in Centum VP, versions R1.07.00 or earlier.

The discovered vulnerability allows an attacker to to perform an out‑of‑bounds memory read in the command handler, because the code fails to validate integer overflow and does not check that length fields of externally‑controlled data match the actual data size.

Vulnerability status: Confirmed by vendor

Date of vulnerability remediation: 13.02.2026

Recommendations:

  • Update to version R1.08.00 or higher

Additional information:

Researcher: Dmitry Sklyar (Positive Technologies)

Identifiers:

CVE-2025-48021

BDU:2025-08838

Vendor:

Yokogawa Electric Corporation

Vulnerable product:

Centum VP

Vulnerable versions:

R1.07.00 or earlier