<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_codesysgmbh/10</id>
  <title>Most recent entries from csaf_codesysgmbh</title>
  <updated>2026-10-02T08:00:04.011192+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/advisory2026-12_vde-2026-097</id>
    <title>Advisory2026-12_VDE-2026-097 — CODESYS Control Runtime - Improper Synchronization in Monitoring</title>
    <updated>2026-09-30T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The monitoring functionality of affected CODESYS Control runtime systems processes read and write requests to PLC application data sent by the CODESYS Development System and other clients such as HMIs.</p>
<p>Due to improper synchronization in the CmpMonitor2 component when processing concurrent requests from multiple clients, incorrect data may be read or written, potentially resulting in unexpected behavior of the affected product.</p>
<p>PLCs based on the CODESYS Runtime Toolkit or CODESYS Safety SIL2 are affected if they allow simultaneous access by two or more clients via the CODESYS protocol. In CODESYS Development System 3, simultaneous access to the included Simulation Runtime can only occur when access by an external client, such as an HMI, has been explicitly enabled through dedicated configuration. The default configuration of CODESYS Development System 3 is not affected.</p>
<p>The vulnerability can be exploited by an authenticated remote attacker with monitoring access by issuing concurrent requests to an affected product.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/advisory2026-12_vde-2026-097"/>
    <published>2026-09-30T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/advisory2026-11_vde-2026-094</id>
    <title>Advisory2026-11_VDE-2026-094 — CODESYS Gateway Client - Uncontrolled Memory Allocation</title>
    <updated>2026-09-30T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The CODESYS Gateway Client (CmpGatewayClient) is used by various CODESYS products to establish PLC communication via the CODESYS Gateway.</p>
<p>Due to missing limits on memory allocations derived from a size field in a gateway response, a malicious gateway can cause excessive memory consumption in the client, resulting in a denial-of-service condition.</p>
<p>The vulnerability can be exploited when an affected product connects to an attacker-controlled gateway.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/advisory2026-11_vde-2026-094"/>
    <published>2026-09-30T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/advisory2026-06_vde-2026-041</id>
    <title>Advisory2026-06_VDE-2026-041 — CODESYS PROFINET Controller - Out-of-bounds Write</title>
    <updated>2026-07-29T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>CODESYS PROFINET is an add‑on for the CODESYS Development System that provides a fully integrated PROFINET protocol stack along with diagnostic capabilities. When a PROFINET Controller is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems.</p>
<p>The vulnerability in the CODESYS PROFINET Controller is caused by an out‑of‑bounds write during the processing of received invalid PROFINET communication data. Triggering this condition causes the CODESYS Control runtime system to handle the resulting exception and stop the affected PLC application in a controlled manner. Remote code execution is not considered feasible, as the execution flow remains controlled.</p>
<p>This issue affects only CODESYS projects that include a PROFINET Controller configuration.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/advisory2026-06_vde-2026-041"/>
    <published>2026-07-29T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/advisory2026-04_vde-2026-040</id>
    <title>Advisory2026-04_VDE-2026-040 — CODESYS EtherNetIP - Improper timeout handling</title>
    <updated>2026-07-13T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>CODESYS EtherNet/IP is an add‑on for the CODESYS Development System that provides a fully integrated EtherNet/IP protocol stack along with diagnostic capabilities. A flaw in the EtherNet/IP adapter protocol stack library results in a vulnerability within the generated application code. When an EtherNet/IP adapter is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems.</p>
<p>Under certain non‑standard operating conditions, the EtherNet/IP adapter fails to perform timeout checks on active TCP connections. As a result, once all available TCP connections are in use, expired connections are not released and no new TCP connections can be established. Existing connections remain unaffected and continue to operate normally.</p>
<p>This issue affects only CODESYS projects that include an EtherNet/IP adapter configuration.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/advisory2026-04_vde-2026-040"/>
    <published>2026-07-13T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/advisory2026-10_vde-2026-057</id>
    <title>Advisory2026-10_VDE-2026-057 — CODESYS Control - Out-of-bounds Write</title>
    <updated>2026-06-18T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The CmpWebServer component in the CODESYS Control Runtime allows users to create browser-based visualizations for monitoring and controlling industrial processes. 
Due to improper bounds checking, a specially crafted HTTP request from an unauthenticated remote attacker may lead to a size-limited out-of-bounds write, causing a denial of service of the affected device.</p>
<p>The CODESYS Control runtime system is only affected if the web server is active, which by default requires a running application with an enabled Web Visualization.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/advisory2026-10_vde-2026-057"/>
    <published>2026-05-26T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/advisory2026-08_vde-2026-056</id>
    <title>Advisory2026-08_VDE-2026-056 — CODESYS Control - Incorrect Authorization</title>
    <updated>2026-06-18T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The CODESYS Control runtime system provides a user management mechanism with multiple privilege groups including the visualization administrators group, which is intended solely to manage visualization users.</p>
<p>Due to insufficient authorization checks an authenticated remote user with low-privileged visualization administrator access can delete higher-privileged accounts. However, independent mechanisms protect the deletion of the last remaining device admin user, preventing a complete loss of administrative access to the device.</p>
<p>The CODESYS Control runtime system is only affected if the optional visualization user management feature is enabled and a visualization administrator account has been configured.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/advisory2026-08_vde-2026-056"/>
    <published>2026-05-26T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/advisory2026-03_vde-2026-018</id>
    <title>Advisory2026-03_VDE-2026-018 — CODESYS Control V3 - Externally-controlled format string in Auditlog</title>
    <updated>2026-06-18T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The CODESYS Control runtime system's CmpAuditLog component allows potentially unauthenticated remote attackers to control the format string of processed log messages. Due to the internal processing logic, the impact is limited to a crash of the CODESYS Control runtime.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/advisory2026-03_vde-2026-018"/>
    <published>2026-03-24T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/advisory2026-02_vde-2026-011</id>
    <title>Advisory2026-02_VDE-2026-011 — CODESYS Control V3 - Untrusted boot application</title>
    <updated>2026-06-18T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The CODESYS Control runtime system provides a user management mechanism with multiple privilege groups. While only the privileged Administrators and Developer groups are intended to load or debug applications on the controller, users in the restricted Service group are allowed to perform maintenance operations, including explicitly replacing the boot application.</p>
<p>In addition to access control, the CODESYS Control runtime system includes an optional application signing feature. When enabled, the controller executes only applications that have been validly signed by authorized developers. However, the CmpApp component of the CODESYS Control runtime systems allows Service‑group users to install a new boot application without requiring any cryptographic validation, if the application signing is not enforced.</p>
<p>As a result, users with Service‑level privileges can install arbitrary boot applications and gain control over the code executed on the controller.</p>
<p>Note: The user group "Service" is a predefined group within the CODESYS Control runtime system. If additional user groups have been created or if the permissions of predefined groups have been modified, then the term "Service" should be understood as a synonym for all groups and their users with no or only limited access rights to the "PlcLogic" object, in conjunction with "Add/Remove" or "Modify" permissions for the boot application files.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/advisory2026-02_vde-2026-011"/>
    <published>2026-03-24T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/advisory2026-09_vde-2026-055</id>
    <title>Advisory2026-09_VDE-2026-055 — CODESYS Development System - Incorrect Default Permissions</title>
    <updated>2026-05-26T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Two local privilege escalation vulnerabilities were identified in the CODESYS Development System. Specifically, the PackageManager and the IPM create temporary directories with insecure default permissions when executed with administrative privileges. This allows low-privileged local users to modify a temporary bootstrap file to force the deployment of arbitrary components, or to exploit a Time-of-Check to Time-of-Use (TOCTOU) race condition to replace digitally verified installation files with malicious ones prior to installation. Both flaws bypass intended security boundaries during the installation of packages or add-ons.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/advisory2026-09_vde-2026-055"/>
    <published>2026-05-26T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/advisory2026-07_vde-2026-052</id>
    <title>Advisory2026-07_VDE-2026-052 — CODESYS Visualization - Insufficiently Protected Credentials</title>
    <updated>2026-05-21T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A vulnerability in the CODESYS Visualization login dialog has been identified. During logins within the CODESYS Visualization, authentication data may not be sufficiently isolated when multiple users perform login operations concurrently.</p>
<p>As a result, an authenticated visualization user may be able to obtain credentials entered by another visualization user. The issue affects only login operations within an active visualization session and can be triggered via local and remote access to the visualization.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/advisory2026-07_vde-2026-052"/>
    <published>2026-05-21T10:00:00+00:00</published>
  </entry>
</feed>
