CVE-2026-79625 PUBLISHED

Improper Synchronization in Monitoring in CODESYS Control Runtime

Assigner: CERTVDE
Reserved: 25.08.2026 Published: 30.09.2026 Updated: 30.09.2026

Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.2

Product Status

Vendor CODESYS
Product Control RTE (SL)
Versions Default: unaffected
  • affected from 3.0.0.0 to 3.5.22.40 (excl.)
Vendor CODESYS
Product Control RTE (for Beckhoff CX) SL
Versions Default: unaffected
  • affected from 3.0.0.0 to 3.5.22.40 (excl.)
Vendor CODESYS
Product Control Win (SL)
Versions Default: unaffected
  • affected from 3.0.0.0 to 3.5.22.40 (excl.)
Vendor CODESYS
Product Runtime Toolkit
Versions Default: unaffected
  • affected from 3.0.0.0 to 3.5.22.40 (excl.)
Vendor CODESYS
Product Safety SIL2
Versions Default: unaffected
  • affected from 3.0.0.0 to 3.5.22.40 (excl.)
Vendor CODESYS
Product HMI (SL)
Versions Default: unaffected
  • affected from 3.0.0.0 to 3.5.22.40 (excl.)
Vendor CODESYS
Product Development System 3
Versions Default: unaffected
  • affected from 3.0.0.0 to 3.5.22.40 (excl.)
Vendor CODESYS
Product Control for BeagleBone SL
Versions Default: unaffected
  • affected from 3.5.0.0 to 4.23.0.0 (excl.)
Vendor CODESYS
Product Control for emPC-A/iMX6 SL
Versions Default: unaffected
  • affected from 3.5.0.0 to 4.23.0.0 (excl.)
Vendor CODESYS
Product Control for IOT2000 SL
Versions Default: unaffected
  • affected from 3.5.0.0 to 4.23.0.0 (excl.)
Vendor CODESYS
Product Control for Linux ARM SL
Versions Default: unaffected
  • affected from 3.5.0.0 to 4.23.0.0 (excl.)
Vendor CODESYS
Product Control for Linux SL
Versions Default: unaffected
  • affected from 3.5.0.0 to 4.23.0.0 (excl.)
Vendor CODESYS
Product Control for PFC100 SL
Versions Default: unaffected
  • affected from 3.5.0.0 to 4.23.0.0 (excl.)
Vendor CODESYS
Product Control for PFC200 SL
Versions Default: unaffected
  • affected from 3.5.0.0 to 4.23.0.0 (excl.)
Vendor CODESYS
Product Control for PLCnext SL
Versions Default: unaffected
  • affected from 3.5.0.0 to 4.23.0.0 (excl.)
Vendor CODESYS
Product Control for Raspberry Pi SL
Versions Default: unaffected
  • affected from 3.5.0.0 to 4.23.0.0 (excl.)
Vendor CODESYS
Product Control for WAGO Touch Panels 600 SL
Versions Default: unaffected
  • affected from 3.5.0.0 to 4.23.0.0 (excl.)
Vendor CODESYS
Product Virtual Control SL
Versions Default: unaffected
  • affected from 3.5.0.0 to 4.23.0.0 (excl.)

References

Problem Types

  • CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CWE