CODESYS PROFINET Controller - Out-of-bounds Write
MonitorCVSS 6.5VDE-2026-041Jul 29, 2026
CODESYSManufacturing
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
An out-of-bounds write vulnerability exists in the CODESYS PROFINET Controller (versions 4.4.0.0 through 4.7.x) when processing invalid PROFINET protocol data. The vulnerability causes an unhandled exception in the CODESYS Control runtime system, stopping the PLC application. This affects only CODESYS projects that include a PROFINET Controller configuration. Remote code execution is not feasible due to controlled exception handling.
What this means
What could happen
An attacker on the local network can send malformed PROFINET packets that cause the PLC application to crash and stop, interrupting any industrial process the controller is managing.
Who's at risk
Manufacturers and utilities operating CODESYS Control runtime systems with PROFINET Controller configurations. This affects any PLC or industrial controller using CODESYS Development System with the PROFINET add-on, particularly in manufacturing and process industries where PROFINET is used for real-time device communication.
How it could be exploited
An attacker sends crafted PROFINET packets with invalid data to a device running the vulnerable CODESYS PROFINET Controller. The out-of-bounds write occurs during packet processing, triggering an exception that halts the PLC application. No remote code execution is possible, but denial of service is achieved.
Prerequisites
- Network access to the PLC on the PROFINET network segment
- PLC configured with a PROFINET Controller in its CODESYS application
- No authentication required
Remotely exploitableLow complexityNo authentication requiredDenial of service (process interruption)Affects industrial automation systems
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (1)
ProductAffected VersionsFix Status
PROFINET 4.4.0.0 < 4.8.0.0≥ 4.4.0.0, < 4.8.0.04.8.0.0
Remediation & Mitigation
0/4
Schedule — requires maintenance window
0/3Patching may require device reboot — plan for process interruption
HOTFIXUpdate CODESYS PROFINET add-on to version 4.8.0.0 or later
HOTFIXIn the CODESYS Development System, update the PROFINET Controller in the device tree to the latest version
HOTFIXDownload the updated CODESYS application to the PLC to activate the fix
Long-term hardening
0/1HARDENINGRestrict network access to the PROFINET network segment to authorized engineering and operational devices only
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/ce800dfd-8a4d-4799-b5af-b4306be0b6d4Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.