CODESYS
CODESYS Control V3 Security Advisory 2025-07
Pages
4
Time to read
4 mins
Publication
Language
English
Pages
4
Time to read
4 mins
Publication
Language
English
This document is a security advisory detailing a vulnerability in the CODESYS Control runtime system that allows low-privileged remote attackers to access the PKI folder via the CODESYS protocol. This access enables attackers to read and write certificates and keys, compromising sensitive cryptographic data and allowing unauthorized certificates to be trusted. The advisory specifies that all services remain operational, but certificate-based encryption and signing features are affected. It lists the products impacted by this vulnerability, including various versions of CODESYS Control. The advisory also outlines the necessary remediation steps, recommending updates to specific product versions to mitigate the risk. Additionally, it provides general security recommendations to enhance system protection, such as using firewalls, encrypted communication, and limiting access. The advisory concludes with acknowledgments and disclaimers regarding liability and the availability of features across different territories.