Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23490 | An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading to a denial-of-service (DoS) condition. |
| Link | Providers |
|---|---|
| https://certvde.com/de/advisories/VDE-2025-070 |
|
Tue, 05 Aug 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Codesys
Codesys control |
|
| Vendors & Products |
Codesys
Codesys control |
Mon, 04 Aug 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 04 Aug 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading to a denial-of-service (DoS) condition. | |
| Title | CODESYS Control DoS via Unauthenticated NULL Pointer Dereference | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-08-04T16:32:30.773Z
Reserved: 2025-04-16T11:17:48.309Z
Link: CVE-2025-41691
Updated: 2025-08-04T16:29:30.560Z
Status : Deferred
Published: 2025-08-04T08:15:48.353
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-41691
No data.
OpenCVE Enrichment
Updated: 2025-08-05T11:38:57Z
EUVD