Back to overview

KEB Automation: Multiple Vulnerabilities in COMBIVIS Control Runtime

VDE-2026-105
Last update
10/08/2026 12:00
Published at
10/08/2026 12:00
Vendor(s)
KEB Automation KG
External ID
VDE-2026-105
CSAF Document

Summary

The Docker-based COMBIVIS Control Runtime service is affected by several vulnerabilities in CODESYS Runtime Toolkit 3.5.21.10. These vulnerabilities are resolved in COMBIVIS Control Runtime 2.1.0.

Impact

These vulnerabilities could expose PKI certificates and their private keys and allow them to be modified. They could also enable unauthenticated remote denial-of-service attacks against affected COMBIVIS Control Runtime systems.

Affected Product(s)

Model no. Product name Affected versions
COMBIVIS Control Runtime vers:generic/>=2.0.0-arm64|<2.1.0-arm64

Vulnerabilities

Expand / Collapse all

Published
10/08/2026 08:52
Weakness
Incorrect Permission Assignment for Critical Resource (CWE-732)
Summary

A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates as trusted. Although all services remain available, only unencrypted communication is possible if the certificates are deleted.

References

Published
10/08/2026 08:52
Weakness
Access of Resource Using Incompatible Type ('Type Confusion') (CWE-843)
Summary

An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.

References

Published
10/08/2026 08:52
Weakness
NULL Pointer Dereference (CWE-476)
Summary

An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading to a denial-of-service (DoS) condition.

References

Published
10/08/2026 08:52
Weakness
Out-of-bounds Read (CWE-125)
Summary

An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.

References

Remediation

Update the COMBIVIS Control Runtime service to version 2.1.0. This version uses CODESYS Runtime Toolkit 3.5.21.50 and resolves the vulnerabilities listed in this advisory.

Service updates can be installed directly on the device through the App Manager service in the web interface. Alternatively, updates can be installed through the NOA Cloud Portal at https://noa.keb-automation.com/.

Acknowledgments

KEB Automation KG thanks the following parties for their efforts:

  • CERT@VDE for coordination.

Revision History

Version Date Summary
1.0.0 10/08/2026 12:00 Initial release