Zurück zur Übersicht

CODESYS Control Runtime - Improper Synchronization in Monitoring

VDE-2026-097
Last update
30.09.2026 12:00
Published at
30.09.2026 12:00
Vendor(s)
CODESYS GmbH
External ID
Advisory2026-12_VDE-2026-097
CSAF Document

Summary

The monitoring functionality of affected CODESYS Control runtime systems processes read and write requests to PLC application data sent by the CODESYS Development System and other clients such as HMIs.

Due to improper synchronization in the CmpMonitor2 component when processing concurrent requests from multiple clients, incorrect data may be read or written, potentially resulting in unexpected behavior of the affected product.

PLCs based on the CODESYS Runtime Toolkit or CODESYS Safety SIL2 are affected if they allow simultaneous access by two or more clients via the CODESYS protocol. In CODESYS Development System 3, simultaneous access to the included Simulation Runtime can only occur when access by an external client, such as an HMI, has been explicitly enabled through dedicated configuration. The default configuration of CODESYS Development System 3 is not affected.

The vulnerability can be exploited by an authenticated remote attacker with monitoring access by issuing concurrent requests to an affected product.

Impact

Successful exploitation may allow an authenticated remote attacker with monitoring access to cause incorrect data processing, malfunction of the affected products, or a denial-of-service condition.

Affected Product(s)

Model no. Product name Affected versions
CODESYS Control RTE (SL) vers:generic/>=3.0.0.0|<3.5.22.40
CODESYS Control RTE (for Beckhoff CX) SL vers:generic/>=3.0.0.0|<3.5.22.40
CODESYS Control Win (SL) vers:generic/>=3.0.0.0|<3.5.22.40
CODESYS Control for BeagleBone SL vers:generic/>=3.5.0.0|<4.23.0.0
CODESYS Control for IOT2000 SL vers:generic/>=3.5.0.0|<4.23.0.0
CODESYS Control for Linux ARM SL vers:generic/>=3.5.0.0|<4.23.0.0
CODESYS Control for Linux SL vers:generic/>=3.5.0.0|<4.23.0.0
CODESYS Control for PFC100 SL vers:generic/>=3.5.0.0|<4.23.0.0
CODESYS Control for PFC200 SL vers:generic/>=3.5.0.0|<4.23.0.0
CODESYS Control for PLCnext SL vers:generic/>=3.5.0.0|<4.23.0.0
CODESYS Control for Raspberry Pi SL vers:generic/>=3.5.0.0|<4.23.0.0
CODESYS Control for WAGO Touch Panels 600 SL vers:generic/>=3.5.0.0|<4.23.0.0
CODESYS Control for emPC-A/iMX6 SL vers:generic/>=3.5.0.0|<4.23.0.0
CODESYS Development System 3 vers:generic/>=3.0.0.0|<3.5.22.40
CODESYS HMI (SL) vers:generic/>=3.0.0.0|<3.5.22.40
CODESYS Runtime Toolkit vers:generic/>=3.0.0.0|<3.5.22.40
CODESYS Safety SIL2 vers:generic/>=3.0.0.0|<3.5.22.40
CODESYS Virtual Control SL vers:generic/>=3.5.0.0|<4.23.0.0

Vulnerabilities

Expand / Collapse all

Published
30.09.2026 11:24
Weakness
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') (CWE-362)
Summary

Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.

References

Remediation

Update the following products to version 3.5.22.40.
* CODESYS Control RTE (SL)
* CODESYS Control RTE (for Beckhoff CX) SL
* CODESYS Control Win (SL)
* CODESYS Runtime Toolkit
* CODESYS Safety SIL2
* CODESYS HMI (SL)
* CODESYS Development System 3

Update the following products to version 4.23.0.0. The release of this version is expected in Q4 2026.
* CODESYS Control for BeagleBone SL
* CODESYS Control for emPC-A/iMX6 SL
* CODESYS Control for IOT2000 SL
* CODESYS Control for Linux ARM SL
* CODESYS Control for Linux SL
* CODESYS Control for PFC100 SL
* CODESYS Control for PFC200 SL
* CODESYS Control for PLCnext SL
* CODESYS Control for Raspberry Pi SL
* CODESYS Control for WAGO Touch Panels 600 SL
* CODESYS Virtual Control SL

The CODESYS Development System and the products available as CODESYS add-ons can be downloaded and installed directly with the CODESYS Installer or be downloaded from the CODESYS Store. Alternatively, as well as for all other products, you will find further information on obtaining the software update in the CODESYS Update area https://www.codesys.com/download/.

Acknowledgments

CODESYS GmbH thanks the following parties for their efforts:

Revision History

Version Date Summary
1.0.0 30.09.2026 12:00 Initial revision.