PT-2025-31799 · Codesys · Codesys Control
Luca Borzacchiello
·
Published
2025-08-04
·
Updated
2026-04-27
·
CVE-2025-41659
CVSS v2.0
8.7
High
| AV:N/AC:L/Au:S/C:C/I:C/A:P |
Name of the Vulnerable Software and Affected Versions
CODESYS Control (affected versions not specified)
Description
A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system. This allows the attacker to read and write certificates and their keys, potentially enabling the extraction of sensitive data or the acceptance of certificates as trusted. If the certificates are deleted, only unencrypted communication is possible, while all services remain available.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Codesys Control