Impact
The vulnerability is a race condition in the monitoring subsystem of various CODESYS Control Runtime products. When multiple clients issue concurrent monitoring commands, the system can read or write incorrect data or corrupt internal memory. The improper synchronization can lead to corrupted function blocks, logs, or other control data and can prevent the system from operating normally. An attacker that is authenticated and has monitoring privileges could exploit the flaw to cause data inconsistencies or to crash the runtime, effectively denying legitimate operation.
Affected Systems
Affected are several CODESYS Control Runtime and associated products, including the standard runtime, Beckhoff CX and PLCnext runtimes, as well as Linux, ARM, Raspberry Pi, BeagleBone, WAGO Touch Panel, emPC-A/iMX6, and virtual control variants, along with the CODESYS development system, HMI, runtime toolkit, safety SIL2, and virtual control SL. Specific version information is not provided in the advisory.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity; the EPSS score is not available, but the absence of a KEV listing suggests no widespread commercial exploitation is documented yet. The vulnerability requires authenticated remote access with monitoring privileges, which implies that an attacker must first be recognized by the system. Once authenticated, the attacker could issue concurrent monitoring requests that trigger the race condition and produce a denial of service or corrupt data. As the attack vector involves remote privileged access, additional controls can mitigate the impact until patches become available.
OpenCVE Enrichment