An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in a controlled stop of the PLC application.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-041/ |
|
History
Wed, 29 Jul 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Codesys profinet
|
|
| Vendors & Products |
Codesys profinet
|
Wed, 29 Jul 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in a controlled stop of the PLC application. | |
| Title | Out-of-bounds Write in CODESYS PROFINET Controller | |
| First Time appeared |
Codesys
Codesys codesys Profinet |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:codesys:codesys_profinet:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Codesys
Codesys codesys Profinet |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-07-29T07:05:57.508Z
Reserved: 2026-04-01T19:54:21.499Z
Link: CVE-2026-35226
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-29T08:30:04Z