CODESYS PROFINET Controller - Out-of-bounds Write

MonitorCVSS 6.5VDE-2026-041Jul 29, 2026
CODESYSManufacturing
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

An out-of-bounds write vulnerability exists in the CODESYS PROFINET Controller (versions 4.4.0.0 through 4.7.x) when processing invalid PROFINET protocol data. The vulnerability causes an unhandled exception in the CODESYS Control runtime system, stopping the PLC application. This affects only CODESYS projects that include a PROFINET Controller configuration. Remote code execution is not feasible due to controlled exception handling.

What this means
What could happen
An attacker on the local network can send malformed PROFINET packets that cause the PLC application to crash and stop, interrupting any industrial process the controller is managing.
Who's at risk
Manufacturers and utilities operating CODESYS Control runtime systems with PROFINET Controller configurations. This affects any PLC or industrial controller using CODESYS Development System with the PROFINET add-on, particularly in manufacturing and process industries where PROFINET is used for real-time device communication.
How it could be exploited
An attacker sends crafted PROFINET packets with invalid data to a device running the vulnerable CODESYS PROFINET Controller. The out-of-bounds write occurs during packet processing, triggering an exception that halts the PLC application. No remote code execution is possible, but denial of service is achieved.
Prerequisites
  • Network access to the PLC on the PROFINET network segment
  • PLC configured with a PROFINET Controller in its CODESYS application
  • No authentication required
Remotely exploitableLow complexityNo authentication requiredDenial of service (process interruption)Affects industrial automation systems
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (1)
ProductAffected VersionsFix Status
PROFINET 4.4.0.0 < 4.8.0.0≥ 4.4.0.0, < 4.8.0.04.8.0.0
Remediation & Mitigation
0/4
Schedule — requires maintenance window
0/3

Patching may require device reboot — plan for process interruption

HOTFIXUpdate CODESYS PROFINET add-on to version 4.8.0.0 or later
HOTFIXIn the CODESYS Development System, update the PROFINET Controller in the device tree to the latest version
HOTFIXDownload the updated CODESYS application to the PLC to activate the fix
Long-term hardening
0/1
HARDENINGRestrict network access to the PROFINET network segment to authorized engineering and operational devices only
API: /api/v1/advisories/ce800dfd-8a4d-4799-b5af-b4306be0b6d4

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

CODESYS PROFINET Controller - Out-of-bounds Write | CVSS 6.5 - OTPulse