Executive brief
A vulnerability exists in the CODESYS PROFINET Controller, a component used in industrial automation to manage communication between controllers and field devices. An attacker on the same local network can send specially crafted data to crash the Programmable Logic Controller (PLC) application. This results in a controlled stop of the industrial process, potentially leading to operational downtime until the system is manually restarted.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the CODESYS PROFINET protocol stack during the processing of received PROFINET communication data. The flaw is located within the PROFINET Controller add-on, which is executed by the CODESYS Control runtime system. An unauthenticated attacker with adjacent network access can send malformed packets to trigger an exception. While the runtime system handles the exception to prevent arbitrary code execution, it results in a Denial of Service (DoS) by forcing the PLC application into a controlled stop. The vulnerability is resolved in version 4.8.0.0; users must update the component in their project device tree and redeploy the application to the PLC for the fix to take effect.
Affected products
- CODESYS CODESYS PROFINET >= 4.4.0.0, < 4.8.0.0
Timeline
- 2026-07-29: disclosed: Initial revision of VDE-2026-041 published
- 2026-07-29: patched: Update to version 4.8.0.0 released