Operational Context & Flaw Overview

Industrial automation giant Yokogawa Electric Corporation and the Cybersecurity and Infrastructure Security Agency (CISA) have issued critical advisories regarding a memory corruption vulnerability designated CVE-2026-61845 (CVSS v3.1 9.8) affecting CENTUM VP Field Control Station (FCS) units. The vulnerability permits remote adversaries with network access to the proprietary Vnet/IP industrial bus to execute arbitrary machine instructions on the embedded realtime controller processor or force the station into an unrecoverable fail-safe halt.

Vulnerability Mechanics & Protocol Analysis

CENTUM VP is one of the most widely deployed Distributed Control Systems (DCS) across petrochemical refining, liquefied natural gas (LNG) terminals, power generation plants, and pharmaceutical continuous manufacturing. The FCS units (including models AFV10D, AFV30D, AFV40D, and CP461) govern continuous process loops, reading sensor analog inputs and driving pneumatic control valves in real time.

Communication between the Human Interface Station (HIS), engineering workstations, and FCS controllers occurs over the Vnet/IP protocol, a proprietary UDP-based realtime network running over standard Ethernet infrastructure. The flaw stems from an integer underflow condition within the FCS Vnet/IP packet parsing subsystem:

Purdue Model Architecture:
[Level 3: Operations LAN / Engineering Station]
                 |  (Vnet/IP Gateway)
[Level 2: Supervisory Control / Vnet/IP Domain]
                 |  (UDP Port 10243 Packet Parsing Flaw)
[Level 1: Yokogawa CENTUM VP FCS Controller]
   ├── AFV30D Duplex Processor Unit (Target of CVE-2026-61845)
   └── FIO Field Network Interface Units (Level 0 Sensors & Valves)

When processing fragmented supervisory command packets on UDP port 10243, the embedded parsing firmware fails to validate payload length boundaries before performing memory copy operations to static internal buffers. By transmitting a sequence of crafted UDP frames, an attacker can corrupt internal execution pointers, diverting CPU execution to attacker-controlled memory regions.

Physical Process Impact

In industrial control environments, remote code execution on a Level 1 DCS controller represents the highest tier of kinetic hazard. Potential consequences include:

  • Silent Setpoint Overwrite: Changing proportional-integral-derivative (PID) loop setpoints without triggering alarms on the operator's Human Interface Station (HIS).
  • Safety Interlock Invalidation: Overwriting digital logic gates governing emergency shutdown thresholds, preventing automated flare or pressure relief systems from tripping.
  • Distributed Plant Outage: Crashing redundant duplex controllers simultaneously, causing immediate valve freezes and emergency shut-ins across production trains.

Remediation & Defensive Architecture

Asset owners must execute the following remediation roadmap in coordination with Yokogawa field engineers:

  • Firmware Deployment: Flash Yokogawa FCS controller firmware to revision R6.10.10 or later during planned plant turnaround windows.
  • Vnet/IP Packet Filtering: Program industrial firewalls (such as Cisco ISA 3000 or Hirschmann Eagle) to drop all Vnet/IP UDP traffic originating outside authorized Level 2 supervisory subnets.
  • IEC 62443 Conduit Verification: Isolate engineering workstations from internet-facing business IT networks in strict compliance with IEC 62443-3-3 System Security Requirements.