Back to overview

CODESYS Key physical side-channel vulnerability

VDE-2025-001
Last update
06/05/2025 15:31
Published at
01/21/2025 12:00
Vendor(s)
CODESYS GmbH
External ID
Advisory2025-01_VDE-2025-001
CSAF Document

Summary

The CODESYS Key USB dongle, which is based on WIBU CodeMeter technology, is affected by a physical side-channel vulnerability.

Impact

The CODESYS Key is a USB dongle for secure storage of your CODESYS software licenses based on WIBU CodeMeter technology. The manufacturer WIBU-SYSTEMS AG has reported a physical side-channel vulnerability in a cryptographic library from Infineon Technologies that is part of the WIBU CmDongle firmware and thus also in the affected CODESYS Keys.

The exploitation of this vulnerability has been classified as complex. Potential attackers need physical access to the CODESYS Key and special equipment to exploit the vulnerability.

For more details see the WIBU-SYSTEMS AG Security Advisory WIBU-100094 on www.wibu.com/support/security-advisor....

In addition to licensing, the CODESYS Key can also be used for secure storage of secret data. The identified CVSS is the highest rating that can occur in combination with the various applications in the CODESYS software. If the CODESYS key is also used with applications from other vendors, the rating may differ. In this case, the respective vendor and/or the WIBU-SYSTEMS AG security advisory should be consulted.

Affected Product(s)

Model no. Product name Affected versions
CODESYS Key series 3 Firmware <4.52

Vulnerabilities

Expand / Collapse all

Published
09/22/2025 14:57
Weakness
Observable Discrepancy (CWE-203)
References

Mitigation

Regardless of the vulnerability described here, CODESYS GmbH recommends that physical access to the CODESYS Key should only be granted to authorized persons. Especially in the case of productive control systems, removal of the CODESYS Key can affect the controlled machine or process.

This generally recommended restriction of access also reduces the attack surface for this vulnerability, as its exploitation requires physical access.

Remediation

Update the CODESYS Key firmware to version 4.52.

Updating the firmware also protects the future usage of additional CODESYS Key features by the CODESYS software and general usage by other software. The update can be installed, for example, via the CodeMeter Control Center.

Revision History

Version Date Summary
1 01/14/2025 12:00 Initial revision.
2 06/05/2025 15:31 Fix: version space