CODESYS Control - Linux/QNX SysSocket flaw
Vulnerability Description
An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41739
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- ABB AG
More from CODESYS
View All →Affected Vendor
CODESYS
View all reports →