Summary
The Docker-based COMBIVIS Control Runtime service is affected by several vulnerabilities in CODESYS Runtime Toolkit 3.5.21.10. These vulnerabilities are resolved in COMBIVIS Control Runtime 2.1.0.
Impact
These vulnerabilities could expose PKI certificates and their private keys and allow them to be modified. They could also enable unauthenticated remote denial-of-service attacks against affected COMBIVIS Control Runtime systems.
Affected Product(s)
| Model no. | Product name | Affected versions |
|---|---|---|
| COMBIVIS Control Runtime | vers:generic/>=2.0.0-arm64|<2.1.0-arm64 |
Vulnerabilities
Expand / Collapse allA low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates as trusted. Although all services remain available, only unencrypted communication is possible if the certificates are deleted.
An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.
An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading to a denial-of-service (DoS) condition.
An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.
Remediation
Update the COMBIVIS Control Runtime service to version 2.1.0. This version uses CODESYS Runtime Toolkit 3.5.21.50 and resolves the vulnerabilities listed in this advisory.
Service updates can be installed directly on the device through the App Manager service in the web interface. Alternatively, updates can be installed through the NOA Cloud Portal at https://noa.keb-automation.com/.
Acknowledgments
KEB Automation KG thanks the following parties for their efforts:
- CERT@VDE for coordination.
Revision History
| Version | Date | Summary |
|---|---|---|
| 1.0.0 | 10/08/2026 12:00 | Initial release |