Description
An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading to a denial-of-service (DoS) condition.
Reserved 2025-04-16 | Published 2025-08-04 | Updated 2025-08-04 | Assigner
CERTVDEHIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Problem types
CWE-476 NULL Pointer Dereference
Product status
Default status
unaffected
3.5.21.10 before 3.5.21.20
affected
Default status
unaffected
3.5.21.10 before 3.5.21.20
affected
Default status
unaffected
3.5.21.10 before 3.5.21.20
affected
Default status
unaffected
3.5.21.10 before 3.5.21.20
affected
Default status
unaffected
4.16.0.0 before 4.17.0.0
affected
Default status
unaffected
4.16.0.0 before 4.17.0.0
affected
Default status
unaffected
4.16.0.0 before 4.17.0.0
affected
Default status
unaffected
4.16.0.0 before 4.17.0.0
affected
Default status
unaffected
4.16.0.0 before 4.17.0.0
affected
Default status
unaffected
4.16.0.0 before 4.17.0.0
affected
Default status
unaffected
4.16.0.0 before 4.17.0.0
affected
Default status
unaffected
4.16.0.0 before 4.17.0.0
affected
Default status
unaffected
4.16.0.0 before 4.17.0.0
affected
Default status
unaffected
4.16.0.0 before 4.17.0.0
affected
Default status
unaffected
4.16.0.0 before 4.17.0.0
affected
References
certvde.com/de/advisories/VDE-2025-070
cve.org (CVE-2025-41691)
nvd.nist.gov (CVE-2025-41691)
Download JSON