High7.7
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

PT-2026-14: Integer underflow leads to Remote Code Execution in Yokogawa Centum VP

Error type:

  • CWE-191:Integer Underflow (Wrap or Wraparound)

Vulnerability vector:

  • Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

  • Severity (CVSSv4.0): 7.7 (High)

Description:

The vulnerability was identified in Centum VP, versions R1.07.00 or earlier.

The discovered vulnerability allows an attacker to achieve remote code execution via an integer underflow that lets malicious input manipulate internal calculations and trigger execution of the code.

Vulnerability status: Confirmed by vendor

Date of vulnerability remediation: 13.02.2026

Recommendations:

  • Update to version R1.08.00 or higher

Additional information:

Researcher: Demid Uzenkov (Positive Technologies)

Identifiers:

CVE-2025-1924

BDU:2025-02823

Vendor:

Yokogawa Electric Corporation

Vulnerable product:

Centum VP

Vulnerable versions:

R1.07.00 or earlier