[Advisory2026-06_VDE-2026-041] CODESYS PROFINET is an add‑on for the CODESYS Development System that provides a fully integrated PROFINET protocol stack along with diagnostic capabilities. When a PROFINET Controller is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems. The vulnerability in the CODESYS PROFINET Controller is caused by an out‑of‑bounds write during the processing of received invalid PROFINET communication data. Triggering…
[Advisory2026-04_VDE-2026-040] CODESYS EtherNet/IP is an add‑on for the CODESYS Development System that provides a fully integrated EtherNet/IP protocol stack along with diagnostic capabilities. A flaw in the EtherNet/IP adapter protocol stack library results in a vulnerability within the generated application code. When an EtherNet/IP adapter is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems. Under certain non‑standard operating…
[Advisory2026-02_VDE-2026-011] The CODESYS Control runtime system provides a user management mechanism with multiple privilege groups. While only the privileged Administrators and Developer groups are intended to load or debug applications on the controller, users in the restricted Service group are allowed to perform maintenance operations, including explicitly replacing the boot application. In addition to access control, the CODESYS Control runtime system includes an optional application…
[Advisory2026-03_VDE-2026-018] The CODESYS Control runtime system's CmpAuditLog component allows potentially unauthenticated remote attackers to control the format string of processed log messages. Due to the internal processing logic, the impact is limited to a crash of the CODESYS Control runtime.
[Advisory2026-08_VDE-2026-056] The CODESYS Control runtime system provides a user management mechanism with multiple privilege groups including the visualization administrators group, which is intended solely to manage visualization users. Due to insufficient authorization checks an authenticated remote user with low-privileged visualization administrator access can delete higher-privileged accounts. However, independent mechanisms protect the deletion of the last remaining device admin user,…
[Advisory2026-10_VDE-2026-057] The CmpWebServer component in the CODESYS Control Runtime allows users to create browser-based visualizations for monitoring and controlling industrial processes. Due to improper bounds checking, a specially crafted HTTP request from an unauthenticated remote attacker may lead to a size-limited out-of-bounds write, causing a denial of service of the affected device. The CODESYS Control runtime system is only affected if the web server is active, which by default…
[Advisory2026-09_VDE-2026-055] Two local privilege escalation vulnerabilities were identified in the CODESYS Development System. Specifically, the PackageManager and the IPM create temporary directories with insecure default permissions when executed with administrative privileges. This allows low-privileged local users to modify a temporary bootstrap file to force the deployment of arbitrary components, or to exploit a Time-of-Check to Time-of-Use (TOCTOU) race condition to replace digitally…
[Advisory2026-07_VDE-2026-052] A vulnerability in the CODESYS Visualization login dialog has been identified. During logins within the CODESYS Visualization, authentication data may not be sufficiently isolated when multiple users perform login operations concurrently. As a result, an authenticated visualization user may be able to obtain credentials entered by another visualization user. The issue affects only login operations within an active visualization session and can be triggered via…
[Advisory2026-05_VDE-2026-042] CODESYS Modbus is an add‑on for the CODESYS Development System that provides a fully integrated Modbus protocol stack along with diagnostic capabilities. A flaw in the CODESYS Modbus TCP Server protocol stack library results in a vulnerability. When a Modbus TCP server is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems. The vulnerability is caused by a resource management issue in the Modbus TCP server…