This product lacks
HSTS (HTTP Strict Transport Security) configuration. When an attacker performs
a Man in the middle (MITM) attack, communications with the web server could be
sniffed.
The
affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to
R10.04
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 09 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yokogawa
Yokogawa fast/tools |
|
| Vendors & Products |
Yokogawa
Yokogawa fast/tools |
Mon, 09 Feb 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product lacks HSTS (HTTP Strict Transport Security) configuration. When an attacker performs a Man in the middle (MITM) attack, communications with the web server could be sniffed. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04 | |
| Weaknesses | CWE-358 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: YokogawaGroup
Published:
Updated: 2026-02-09T19:06:08.322Z
Reserved: 2025-12-05T05:04:18.583Z
Link: CVE-2025-66600
Updated: 2026-02-09T19:04:11.394Z
Status : Deferred
Published: 2026-02-09T04:15:49.170
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-66600
No data.
OpenCVE Enrichment
Updated: 2026-02-09T10:39:12Z