The Cybersecurity and Infrastructure Security Agency (CISA) and industrial process automation manufacturer Yokogawa Electric Corporation have issued a critical security bulletin (ICSA-26-278-02) detailing a maximum-severity stack buffer overflow (CVE-2026-43890, CVSS 9.8) in Yokogawa CENTUM VP Human Interface Station (HIS) consoles. The vulnerability allows remote attackers on the control system network to take full operational control of chemical, petrochemical, and power generation monitoring systems.
Technical Root Cause: Vnet/IP Alarm Frame Overflow (CWE-121)
Yokogawa CENTUM VP is one of the world's most ubiquitous Distributed Control Systems (DCS), overseeing continuous production at major industrial facilities. Operator Human Interface Stations (HIS) communicate with Field Control Stations (FCS) using Yokogawa's proprietary Vnet/IP protocol, a deterministic real-time Ethernet network.
The flaw resides in the HIS background telemetry receiver service (BKHOpmSvc.exe), which monitors UDP broadcast packets for real-time process alarm updates. When handling an oversized tag description block, the function uses an unsafe strcpy call into a fixed 256-byte stack frame:
// Disassembly representation of vulnerable Vnet/IP alarm frame parser
void ProcessAlarmNotification(char* raw_packet_data, int packet_len) {
char tag_buffer[256];
char* tag_ptr = ExtractTagField(raw_packet_data);
// Unsafe string copy without bounds validation
strcpy(tag_buffer, tag_ptr); // Overwrites saved return address on stack
DisplayAlarmBanner(tag_buffer);
}
By broadcasting a crafted UDP packet on the Vnet/IP network segment (port 51000/UDP), an attacker can reliably seize the processor execution flow, executing shellcode with SYSTEM privileges on the Windows-based operator console.
Industrial Safety & Operational Impact
Once compromised, the HIS workstation provides unrestricted supervisory control over connected Field Control Stations (FCS):
- Setpoint Modification: Attackers can alter critical chemical valve positions, temperature thresholds, and pressure limits while masking the modifications on operator visual displays.
- Safety Instrumented System Disruption: Overriding interlock status can prevent automated shutdown procedures during catastrophic over-pressure scenarios.
- Plant-Wide Blackout: Remote execution enables the adversary to wipe control configuration databases, forcing protracted and hazardous manual cold starts.
Mitigation & Defensive Recommendations
- Apply Official Vendor Patch: Immediately install Yokogawa software update package R6.10.01.
- Strict Vnet/IP Boundary Isolation: Enforce strict firewall rules preventing any non-control system traffic from reaching Vnet/IP domains.
- Disable Unnecessary Broadcast Forwarding: Configure industrial managed switches to discard UDP port 51000 packets originating outside verified FCS subnets.



