CVE-2024-41975: CODESYS (Edge) Gateway for Windows insecure default
An unauthenticated remote attacker can gain limited information of the PLC network but the user management of the PLCs prevents the actual access to the PLCs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41975?
CVE-2024-41975 is considered to have a low severity due to the limited information disclosure and the protective user management of the PLCs.
How do I fix CVE-2024-41975?
To address CVE-2024-41975, ensure that the latest updates and patches for CODESYS Edge Gateway for Windows are applied.
Who is affected by CVE-2024-41975?
CVE-2024-41975 affects users of CODESYS Edge Gateway for Windows who have improperly secured PLC networks.
Can CVE-2024-41975 lead to unauthorized access?
CVE-2024-41975 does not allow for unauthorized access to the PLCs due to user management controls, but it can lead to limited information disclosure.
What actions should I take if my system is affected by CVE-2024-41975?
If your system is affected by CVE-2024-41975, review your network security measures and update your CODESYS Edge Gateway software.