CVE-2025-41738

CWE-8433 documents3 sources
Severity
7.5HIGH
EPSS
0.1%
top 65.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 1

Description

An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages25 packages

NVDcodesys/control4.5.0.04.19.0.0+1
NVDcodesys/control_rte_sl3.5.18.03.5.21.40
NVDcodesys/control_win_sl3.5.18.03.5.21.40
NVDcodesys/runtime_toolkit3.5.18.03.5.21.40
NVDcodesys/remote_target_visu3.5.18.03.5.21.40

🔴Vulnerability Details

2
CVEList
CODESYS Control - Invalid type usage in visualization2025-12-01
GHSA
GHSA-7pvj-rp26-vxxc: An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wro2025-12-01
CVE-2025-41738 (HIGH CVSS 7.5) | An unauthenticated remote attacker | cvebase.io