CVE-2025-41660
8.8CODESYS · CODESYS Control runtime system
A vulnerability in the CODESYS Control runtime system allows a low-privileged remote attacker to replace the boot application, leading to unauthorized code execution.
Executive summary
A critical vulnerability in the CODESYS Control runtime system allows remote attackers with low privileges to achieve unauthorized code execution, posing a significant risk to industrial automation environments.
Vulnerability
The flaw is an instance of CWE-669 (Incorrect Resource Transfer Between Spheres), where improper handling of resource transfers allows a low-privileged authenticated attacker to overwrite the boot application, resulting in arbitrary code execution.
Business impact
Successful exploitation of this vulnerability could lead to a total compromise of the affected industrial control system, resulting in unauthorized process control, operational downtime, or the potential for lateral movement within the production network. Given the CVSS score of 8.8, this flaw represents a high-severity risk that could directly impact system integrity and safety in industrial environments.
Remediation
Immediate Action: Update all affected CODESYS runtime components to version 3.5.22.0 or 4.21.0.0, respectively, as specified in the vendor advisory.
Proactive Monitoring: Monitor network traffic for unauthorized access attempts to the CODESYS runtime service and review system logs for modifications to boot application files.
Compensating Controls: Restrict network access to the CODESYS runtime interface using firewall rules to ensure that only authorized engineering workstations can communicate with the device.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations utilizing CODESYS runtime systems should prioritize this update to prevent potential unauthorized code execution. Given the high CVSS severity and the critical nature of industrial control systems, administrators should verify the integrity of their runtime configurations and apply the vendor-provided patches immediately to mitigate the risk of compromise.
Sources
Originally found and disclosed by Luca Borzacchiello from Nozomi Networks, per the CVE Program record.