CVE-2025-41659: CODESYS Control PKI Exposure Enables Remote Certificate Access
A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates as trusted. Although all services remain available, only unencrypted communication is possible if the certificates are deleted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41659?
CVE-2025-41659 is classified as a low severity vulnerability.
How do I fix CVE-2025-41659?
To remediate CVE-2025-41659, restrict access to the PKI folder and implement appropriate access controls.
What can a low-privileged attacker do with CVE-2025-41659?
A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system to read and write certificates and keys.
Which software is affected by CVE-2025-41659?
CVE-2025-41659 affects the CODESYS Control runtime system.
What are the potential risks associated with CVE-2025-41659?
The risks include the extraction of sensitive data and the acceptance of untrusted certificates as valid.