CVE-2026-79625: Improper Synchronization in Monitoring in CODESYS Control Runtime
Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be remote, authenticated, and have access to the runtime's monitoring functionality. The issue is therefore relevant where monitoring access is available to untrusted or insufficiently trusted accounts.
What impact can successful exploitation have?
Concurrent monitoring requests can cause incorrect reads or writes, corruption of internal memory structures, incorrect data processing, or a denial-of-service condition. The provided impact information indicates integrity and availability effects, with no confidentiality impact stated.
What attacker action is required to trigger the condition?
The attacker needs to send concurrent requests through the monitoring functionality. No user interaction is required.