7.5

CVE-2025-41738

An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CodesysControl For Beaglebone Sl Version >= 4.5.0.0 < 4.19.0.0
CodesysControl For Empc-a/imx6 Sl Version >= 4.5.0.0 <= 4.19.0.0
CodesysControl For Iot2000 Sl Version >= 4.5.0.0 < 4.19.0.0
CodesysControl For Linux Arm Sl Version >= 4.5.0.0 < 4.19.0.0
CodesysControl For Linux Sl Version >= 4.5.0.0 < 4.19.0.0
CodesysControl For Pfc100 Sl Version >= 4.5.0.0 <= 4.19.0.0
CodesysControl For Pfc200 Sl Version >= 4.5.0.0 < 4.19.0.0
CodesysControl For Plcnext Sl Version >= 4.5.0.0 < 4.19.0.0
CodesysControl For Raspberry Pi Sl Version >= 4.5.0.0 < 4.19.0.0
CodesysControl For Wago Touch Panels 600 Sl Version >= 4.5.0.0 <= 4.19.0.0
CodesysControl Rte Sl Version >= 3.5.18.0 < 3.5.21.40
CodesysControl Rte Sl (for Beckhoff Cx) Version >= 3.5.18.0 < 3.5.21.40
CodesysControl Win Sl Version >= 3.5.18.0 < 3.5.21.40
CodesysHmi Sl Version >= 3.5.18.0 < 3.5.21.40
CodesysRemote Target Visu Version >= 3.5.18.0 < 3.5.21.40
CodesysRuntime Toolkit Version >= 3.5.18.0 < 3.5.21.40
CodesysVirtual Control Sl Version >= 4.5.0.0 < 4.19.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.319
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
info@cert.vde.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.