Executive brief
CODESYS Visualization is a software component used to create and display human-machine interfaces (HMI) for industrial controllers. A security flaw has been identified where login information can be accidentally shared between different users if they attempt to log in at the same time. This could allow a low-privileged user to capture the credentials of a more powerful user, such as an administrator, potentially leading to unauthorized control of industrial equipment.
Technical details
A vulnerability classified as CWE-522 (Insufficiently Protected Credentials) exists in CODESYS Visualization versions prior to 4.10.0.0. The root cause is insufficient isolation of authentication data during concurrent login operations within an active visualization session. An authenticated remote user with low privileges can exploit this race condition to obtain the credentials of another user logging in at the same time. This vulnerability requires user interaction (the victim must be logging in) and can be triggered via both local and remote access. A fix is available in version 4.10.0.0, though existing projects require recompilation and redeployment to the PLC/HMI to be protected.
Affected products
- CODESYS Visualization < 4.10.0.0
Timeline
- 2026-05-21: disclosed: Initial advisory publication by CERT@VDE and CODESYS
- 2026-05-21: patched: Fixed in CODESYS Visualization 4.10.0.0