This document is a security advisory detailing a vulnerability in the CODESYS OPC UA stack within the CODESYS Control runtime system. The advisory outlines that the OPC UA stack may incorrectly calculate the required buffer size for received requests and responses, which can lead to a crash of the runtime system during the initialization of the receive buffer. The advisory lists affected products and specifies versions that are vulnerable. It provides vulnerability identifiers, including CVE-2024-5000, and a CVSS base score indicating a high severity level. The document also describes the potential impact of this vulnerability, including how an attacker could exploit it through crafted requests. Remediation steps are provided, recommending updates to specific product versions to mitigate the issue. Additionally, general security recommendations are included to enhance the security posture of CODESYS products. Acknowledgments for reporting the issue and further information for support are also mentioned.