CVE-2026-79625 Details
Description
Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.
A vulnerability exists in CODESYS Control runtime systems due to improper synchronization in the monitoring component, CmpMonitor2, when handling concurrent requests from multiple clients. This flaw can lead to incorrect data processing, corruption of PLC application data, or a denial-of-service condition. The issue affects various CODESYS Control runtime environments, including those for BeagleBone, IOT2000, Linux ARM, Linux, PFC100, PFC200, PLCnext, Raspberry Pi, WAGO Touch Panels 600, and virtual control, as well as the CODESYS Development System 3, CODESYS HMI, CODESYS Runtime Toolkit, and CODESYS Safety SIL2, all within specific version ranges.
Users are advised to update to version 3.5.22.40 for CODESYS Control RTE (SL), CODESYS Control RTE (for Beckhoff CX) SL, CODESYS Control Win (SL), CODESYS Runtime Toolkit, CODESYS Safety SIL2, CODESYS HMI (SL), and CODESYS Development System 3. For CODESYS Control for BeagleBone SL, CODESYS Control for emPC-A/iMX6 SL, CODESYS Control for IOT2000 SL, CODESYS Control for Linux ARM SL, CODESYS Control for Linux SL, CODESYS Control for PFC100 SL, CODESYS Control for PFC200 SL, CODESYS Control for PLCnext SL, CODESYS Control for Raspberry Pi SL, CODESYS Control for WAGO Touch Panels 600 SL, and CODESYS Virtual Control SL, the update to version 4.23.0.0 is expected in Q4 2026.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-097/ | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-362 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CODESYS Control RTE | >= 3.0.0.0, < 3.5.22.40 |
CPE
Remediation
| |
| CODESYS Control Win | >= 3.0.0.0, < 3.5.22.40 |
CPE
Remediation
| |
| CODESYS Control | >= 3.5.0.0, < 4.23.0.0 ~3.0 |
CPE
Remediation
| |
| CODESYS Development System | >= 3.0.0.0, < 3.5.22.40 |
CPE
Remediation
| |
| CODESYS HMI | >= 3.0.0.0, < 3.5.22.40 |
CPE
Remediation
| |
| CODESYS Runtime Toolkit | >= 3.0.0.0, < 3.5.22.40 |
CPE
Remediation
| |
| CODESYS Safety SIL2 | >= 3.0.0.0, < 3.5.22.40 |
CPE
Remediation
| |
| CODESYS Virtual Control | >= 3.5.0.0, < 4.23.0.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion