Home
HIGH: 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HDefault status
unaffected
0.0.0 (semver) before 3.5.21.40
affected
Description
An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.
Problem types
CWE-502 Deserialization of Untrusted Data
Product status
0.0.0 (semver) before 3.5.21.40
Credits
MengyuXia from Beijing Aerospace Wanyuan Science & Technology Co, Ltd.
References
certvde.com/de/advisories/VDE-2025-101