CVE-2026-11833 Details
Description
Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing the CI Server setting information. This information could be exploited by an attacker for other attacks. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04 CI Server (All packages) R1.01 to R1.04
A vulnerability exists in Yokogawa FAST/TOOLS and CI Server that allows the web server to unintentionally disclose CI Server setting information in its responses. This information leakage could be leveraged by an attacker to facilitate further attacks. The vulnerability affects FAST/TOOLS versions R9.01 to R10.04, across several packages including RVSVRN, UNSVRN, HMIWEB, FTEES, and HMIMOB. Additionally, all packages of CI Server versions R1.01 to R1.04 are affected.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 23, 2026CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://web-material3.yokogawa.com/1/39777/files/YSAR-26-0004-E.pdf | YokogawaGroup | AdvisoryPermission RequiredVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | YokogawaGroup |
Affected Products
| Product | Versions |
|---|---|
| Yokogawa FAST/TOOLS | >= R9.01, <= R10.04 |
CPE
Remediation
| |
| Yokogawa CI Server | >= R1.01, <= R1.04 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | New CVE Received | YokogawaGroup |
Volerion