Impact
The vulnerability is an out‑of‑bounds write in the CODESYS PROFINET Controller that causes an exception in the PLC application. When triggered, the exception is handled by the CODESYS Control runtime, leading to a controlled stop of the PLC. The impact is an availability disruption of the PLC system; there is no direct evidence of confidentiality or integrity compromise. The weakness corresponds to CWE‑787.
Affected Systems
The affected product is the CODESYS PROFINET Controller. All versions of this product are susceptible unless updated to a version that includes the fix; version details are not provided in the advisory.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity. The EPSS score of less than 1 % suggests a low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog. An attacker must be on the same network segment and does not need authentication to send malformed PROFINET data, making the exploitation path relatively simple yet limited to local network reach. The consequence is an interruption of PLC operation, potentially impacting industrial processes but not allowing arbitrary code execution or data disclosure.
OpenCVE Enrichment