Summary
CODESYS PROFINET is an add‑on for the CODESYS Development System that provides a fully integrated PROFINET protocol stack along with diagnostic capabilities. When a PROFINET Controller is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems.
The vulnerability in the CODESYS PROFINET Controller is caused by an out‑of‑bounds write during the processing of received invalid PROFINET communication data. Triggering this condition causes the CODESYS Control runtime system to handle the resulting exception and stop the affected PLC application in a controlled manner. Remote code execution is not considered feasible, as the execution flow remains controlled.
This issue affects only CODESYS projects that include a PROFINET Controller configuration.
Impact
Exploitation of the vulnerability allows an unauthenticated attacker to trigger an exception that is handled by the CODESYS Control runtime system, resulting in a controlled stop of the affected PLC application until it is restarted.
Affected Product(s)
| Model no. | Product name | Affected versions |
|---|---|---|
| CODESYS PROFINET | vers:generic/>=4.4.0.0|<4.8.0.0 |
Vulnerabilities
Expand / Collapse allAn out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in a controlled stop of the PLC application.
Remediation
Update the following product to version 4.8.0.0.
* CODESYS PROFINET
To make the fix effective for existing CODESYS projects, you must additionally update the PROFINET Controller in the device tree to the latest version and perform a download of the CODESYS application to the PLC.
The CODESYS Development System and the products available as CODESYS add-ons can be downloaded and installed directly with the CODESYS Installer or be downloaded from the CODESYS Store. Alternatively, as well as for all other products, you will find further information on obtaining the software update in the CODESYS Update area https://www.codesys.com/download/.
Acknowledgments
CODESYS GmbH thanks the following parties for their efforts:
- CERT@VDE for coordination (see https://www.certvde.com )
- ABB for reporting
Revision History
| Version | Date | Summary |
|---|---|---|
| 1.0.0 | 29.07.2026 12:00 | Initial revision. |