CVE-2026-11833
Received
Received - Intake
Information Disclosure in FAST/TOOLS and CI Server
Publication date: 2026-06-23
Last updated on: 2026-06-23
Assigner: YokogawaGroup
Description
Description
Overview:
A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing the CI Server setting information. This information could
be exploited by an attacker for other attacks.
The affected products and versions are as follows:
FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04
CI ServerΒ (All packages)Β R1.01 to R1.04
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| yokogawa | fast_tools | From 9.01 (inc) to 10.04 (inc) |
| yokogawa | ci_server | From 1.01 (inc) to 1.04 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-319 | The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. |