CVE-2025-7741Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Hardcoded Password Vulnerability have been found in CENTUM. Affected products contain a hardcoded password for the user account (PROG) used for CENTUM Authentication Mode within the system. Under the following conditions, there is a risk that an attacker could log in as the PROG user. The default permission for the PROG users is S1 permission (equivalent to OFFUSER). Therefore, for properly permission-controlled targets of operation and monitoring, even if an attacker user in as the PROG user, the risk of critical operations or configuration changes being performed is considered low. (If the PROG user's permissions have been changed for any reason, there is a risk that operations or configuration changes may be performed under the modified permissions. The CVSS values below are for the default permissions.) Additionally, exploiting this vulnerability requires an attacker to already have access to the HIS screen controls. Therefore, an attacker can already operate and monitor at that point, regardless of this vulnerability. The conditions under which this vulnerability is exploited: If all of the following conditions are met, the affected products are vulnerable to this vulnerability. -An attacker obtains the hardcoded password using a certain method. -The HIS with the affected product installed is configured in CTM authentication mode. -An attacker must have direct access to the aforementioned HIS or be able to break into it remotely using a certain method and perform screen operations. The affected products and versions are as follows: CENTUM VP R5.01.00 to R5.04.20, R6.01.00 to R6.12.00 and R7.01.00.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-259

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-03-30); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-03-30: 2Mentions · 2026-04-02: 2Mentions · 2026-04-15: 1Mentions · 2026-04-18: 1Patch / Workaround · 2026-04-02: 2Technical Details · 2026-03-30: 1Technical Details · 2026-04-02: 2Technical Details · 2026-04-15: 1Technical Details · 2026-04-18: 103-3004-0204-1504-18
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-302
Disclosure2
2026-04-022
Patch2
2026-04-151
General1
2026-04-181
Disclosure1
Full discourse6 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2025-7741 📊 Severity: 2.1 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-7741 #CVE-2025-7741 #CVE #Low #CyberSecurity #InfoSec https://t.co/8OJBnaAaz6

    Post summary

    The tweet announces CVE‑2025‑7741 as a new low‑severity vulnerability and directs readers to the NVD for details, but it provides no technical, exploit, or patch information.

    01000158
    116 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Disclosure

    🔒 #CyberSecurity CVE-2025-7741: Yokogawa CENTUM VP Hardcoded Password — Detection and Hardening … "A hardcoded password in Yokogawa CENTUM VP (CVE-2025-7741) allows attackers to…" 🔗 https://securityarsenal.com/blog/cve-2025-7741-yokogawa-centum-vp-hardcoded-password-detection-and-hardening-guide #CyberSecurity #ThreatIntel #managedsoc #mdr #securitymonitoring

    Post summary

    The tweet announces CVE-2025‑7741, a hardcoded password vulnerability in Yokogawa CENTUM VP, and points to a guide for detection and hardening, but does not provide exploit code, active exploitation evidence, or patch details.

    00000476
    11 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    General

    🔒 #CyberSecurity Defending Against CVE-2025-7741: Hardcoded Password Risk in Yokogawa CENTUM VP "Recent advisories from CISA (ICSA-26-092-02) have highlighted a critical vulnerability in…" 🔗 https://securityarsenal.com/blog/defending-against-cve-2025-7741-hardcoded-password-risk-in-yokogawa-centum-vp #CyberSecurity #ThreatIntel #soc #mdr #managedsoc

    Post summary

    The post highlights CVE‑2025‑7741, a hardcoded password vulnerability in Yokogawa CENTUM VP, offering defensive advice but lacking exploit, patch or active‑exploitation details.

    00000164
    10 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Multiple ICS Vulnerabilities: Hitachi Energy Ellipse JasperReports RCE; Siemens SICAM 8 DoS (XML parsing/resource exhaustion); Yokogawa CENTUM VP hard-coded PROG password 📅 **Timeline:** Disclosure: 2025-09-16, Patch: 2026-03-30 🆔 **CVE-2025-10492** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 59.43% 🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories 📂 **Affected Versions:** Hitachi Ellipse ≤9.0.50 🔧 **Fixed Versions:** Vendor guidance via Hitachi PSIRT/CISA (no fixed version listed) 🫨 **Attack Vectors:** - Java deserialization over network (remote code execution) 📝 **Summary:** A deserialization flaw in the JasperReports component used by Hitachi Ellipse allows remote code execution, risking full system compromise. Exploitation could disrupt ICS operations, impact safety, and enable lateral movement. 📈 **Impact Scope:** ICS/OT systems — remote code execution, potential operational disruption and safety risks. 🛡️ **Recommended Actions:** - Inventory Ellipse instances, isolate affected hosts, and follow Hitachi PSIRT/CISA guidance immediately - Block/validate untrusted deserialization inputs and apply vendor/third‑party library mitigations 🆔 **CVE-2026-27663** | 📊 CVSS: 6.5 (MEDIUM 🟡) | 📈 EPSS: 4.82% 🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories 📂 **Affected Versions:** Siemens CPCI85 <26.10, RTUM85 <26.10, SICORE <26.10.0 🔧 **Fixed Versions:** Siemens update ≥26.10 (SICORE 26.10.0+) 🫨 **Attack Vectors:** - High-volume request/resource exhaustion in remote operation mode (DoS) 📝 **Summary:** A resource-exhaustion vulnerability in Siemens SICAM 8 can cause service degradation or reboot via high-volume requests, impacting availability of control systems. Operational disruption risk is significant for exposed or poorly segmented deployments. 📈 **Impact Scope:** ICS/OT systems — denial-of-service affecting availability and operational continuity. 🛡️ **Recommended Actions:** - Apply Siemens security updates (≥26.10 / SICORE 26.10.0+) and isolate affected devices from untrusted networks - Implement rate-limiting, request validation, and monitoring for anomalous traffic volumes 🆔 **CVE-2026-27664** | 📊 CVSS: 7.5 (HIGH 🟠) | 📈 EPSS: 15.74% 🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories 📂 **Affected Versions:** Siemens CPCI85 <26.10, RTUM85 <26.10, SICORE <26.10.0 🔧 **Fixed Versions:** Siemens update ≥26.10 (SICORE 26.10.0+) 🫨 **Attack Vectors:** - Malformed XML over network leading to out-of-bounds write and service crash (DoS) 📝 **Summary:** A crafted XML input can trigger an out‑of‑bounds write in SICAM 8, causing service crashes and denial-of-service. This threatens availability of monitoring/control functions and may require manual recovery. 📈 **Impact Scope:** ICS/OT systems — denial-of-service and potential operational safety impacts. 🛡️ **Recommended Actions:** - Patch to Siemens 26.10+ (SICORE 26.10.0+) and restrict XML/protocol exposure via network controls - Add input validation, monitoring for crashes, and automated restart/detection safeguards 🆔 **CVE-2025-7741** | 📊 CVSS: 2.1 (LOW 🟢) | 📈 EPSS: 4.39% 🛠️ **Exploit Maturity:** Not Available / No public PoC or confirmed active exploitation reported in advisories 📂 **Affected Versions:** CENTUM VP R5.01.00–<R5.04.20, R6.01.00–<R6.12.00, R7.01.00 🔧 **Fixed Versions:** CENTUM VP R7.01.10, use Windows Authentication for R5/R6 🫨 **Attack Vectors:** - Hard-coded PROG account password allowing authentication with HIS screen/local access 📝 **Summary:** A hard-coded PROG password in CENTUM VP permits authentication if an attacker can access HIS screens, enabling unauthorized actions and privilege misuse. Risk increases where PROG permissions were elevated or HIS access is insufficiently restricted. 📈 **Impact Scope:** ICS/OT systems — unauthorized access, privilege misuse, and potential operational impact. 🛡️ **Recommended Actions:** - Patch to R7.01.10 or switch affected R5/R6 branches to Windows Authentication; restrict HIS screen access - Rotate credentials where possible, enforce least privilege, and monitor PROG account usage 🪢 **Related Resources:** - https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-03 - https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-01 🏷 **Tags:** #Cybersecurity #ICS #OT

    Post summary

    The advisory provides detailed technical information on four high‑severity CVEs affecting Hitachi Ellipse, Siemens SICAM, and Yokogawa CENTUM VP, includes vendor guidance and patch recommendations, but notes no publicly available PoC or confirmed active exploitation.

    00000159
    277 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Multiple ICS Vulnerabilities: Hitachi Ellipse JasperReports RCE; Siemens SICAM 8 DoS/Out-of-bounds; Yokogawa CENTUM VP Hard-coded Password 📅 **Timeline:** Disclosure: unknown, Patch: unknown 🆔 **CVE-2025-10492** | 📊 CVSS: 9.8 (Critical 🔴) | 📈 EPSS: 59.43% 🆔 **CVE-2026-27663** | 📊 CVSS: 6.5 (Medium 🟡) | 📈 EPSS: 4.82% 🆔 **CVE-2026-27664** | 📊 CVSS: 7.5 (High 🟠) | 📈 EPSS: 15.74% 🆔 **CVE-2025-7741** | 📊 CVSS: 4.0 (Low/Medium 🟢) | 📈 EPSS: 4.39% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Hitachi Ellipse ≤9.0.50, Siemens SICAM 8 family (CPCI85/RTUM85/SICORE) <26.10, Yokogawa CENTUM VP R5.x affected (>=R5.01.00 <R5.04.20), Yokogawa CENTUM VP R6.x affected (>=R6.01.00 <R6.12.00), Yokogawa CENTUM VP vR7.01.00 🔧 **Fixed Versions:** Yokogawa: CENTUM VP R7.01.10 (patch) or switch R5/R6 to Windows Auth, Siemens: apply latest SICAM 8 security updates, Hitachi: update Jaspersoft per PSIRT 🫨 **Attack Vectors:** - Java deserialization via Jaspersoft/JasperReports → remote code execution - High-volume remote requests causing resource exhaustion (DoS) - Malformed XML parsing → out-of-bounds write and service crash - Hard-coded PROG account password usable from HIS screen access (local/admin interface) 📝 **Summary:** Multiple high-impact ICS flaws affect Hitachi, Siemens and Yokogawa products: CVE-2025-10492 enables full RCE via a vulnerable Jaspersoft component in Hitachi Ellipse; CVE-2026-27663/27664 allow DoS and crashes in Siemens SICAM 8 components; CVE-2025-7741 is a hard-coded PROG password in Yokogawa CENTUM VP that can enable local privilege misuse. These issues threaten operational availability and can lead to full system compromise in critical manufacturing and energy environments. 📈 **Impact Scope:** Industrial control systems in critical manufacturing, energy, and related sectors; impacts include full RCE, denial-of-service/resource exhaustion and crashes, and local privilege misuse via hard-coded account. 🛡️ **Recommended Actions:** - Apply vendor-provided updates/patches immediately and follow PSIRT advisories - Isolate ICS/HMI networks, minimize exposure of management interfaces, and implement network-level filtering/throttling - Hitachi: remediate/upgrade vulnerable Jaspersoft per PSIRT; Siemens: deploy latest SICAM 8 security updates; Yokogawa: apply R7.01.10 patch or switch R5/R6 to Windows Authentication Mode and review PROG permissions - Monitor for abnormal requests, crashes, and unauthorized logins; test patches in lab before wide deployment 🪢 **Related Resources:** - https://www.cisa.gov/news-events/ics-advisories/icsa-26-092-03 - https://www.cve.org/CVERecord?id=CVE-2025-10492 🏷 **Tags:** #Cybersecurity #ICS #OTsecurity (Remove commas and spaces between tags)

    Post summary

    This advisory details several critical industrial control system vulnerabilities and provides specific patch versions and mitigation steps for Hitachi, Siemens, and Yokogawa products.

    00000141
    277 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-7741 Hardcoded Password Vulnerability have been found in CENTUM. Affected products contain a hardcoded password for the user account (PROG) used for CENTUM Authentication Mo… https://www.cve.org/CVERecord?id=CVE-2025-7741

    Post summary

    CVE-2025-7741 discloses a hardcoded password vulnerability in CENTUM products, exposing a PROG user account used for authentication; no PoC, exploit code, patch, or active exploitation details are provided.

    00000111
    56.9K followersView on X

Explore more