Description
CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.
Reserved 2025-04-16 | Published 2025-08-04 | Updated 2025-08-04 | Assigner
CERTVDEMEDIUM: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Problem types
CWE-276 Incorrect Default Permissions
Product status
Default status
unaffected
0.0.0.0 before 3.5.21.20
affected
Default status
unaffected
0.0.0.0 before 4.16.0.0
affected
Default status
unaffected
0.0.0.0 before 4.16.0.0
affected
Default status
unaffected
0.0.0.0 before 4.16.0.0
affected
Default status
unaffected
0.0.0.0 before 4.16.0.0
affected
Default status
unaffected
0.0.0.0 before 4.16.0.0
affected
Default status
unaffected
0.0.0.0 before 4.16.0.0
affected
Default status
unaffected
0.0.0.0 before 4.16.0.0
affected
Default status
unaffected
0.0.0.0 before 4.16.0.0
affected
Default status
unaffected
0.0.0.0 before 4.16.0.0
affected
Default status
unaffected
0.0.0.0 before 4.16.0.0
affected
Default status
unaffected
0.0.0.0 before 4.16.0.0
affected
Credits
Luca Borzacchiello from Nozomi Networks finder
References
certvde.com/de/advisories/VDE-2025-049
cve.org (CVE-2025-41658)
nvd.nist.gov (CVE-2025-41658)
Download JSON