An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in a controlled stop of the PLC application.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-041/ |
|
History
Wed, 29 Jul 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Codesys profinet
|
|
| Vendors & Products |
Codesys profinet
|
Wed, 29 Jul 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in a controlled stop of the PLC application. | |
| Title | Out-of-bounds Write in CODESYS PROFINET Controller | |
| First Time appeared |
Codesys
Codesys codesys Profinet |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:codesys:codesys_profinet:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Codesys
Codesys codesys Profinet |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-07-29T07:05:57.508Z
Reserved: 2026-04-01T19:54:21.499Z
Link: CVE-2026-35226
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-29T08:30:04Z
Weaknesses