{"api_version":"1","generated_at":"2026-10-01T07:10:01+00:00","cve":"CVE-2026-79625","urls":{"html":"https://cve.report/CVE-2026-79625","api":"https://cve.report/api/cve/CVE-2026-79625.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-79625","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-79625"},"summary":{"title":"Improper Synchronization in Monitoring in CODESYS Control Runtime","description":"Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.","state":"PUBLISHED","assigner":"CERTVDE","published_at":"2026-09-30 10:17:17","updated_at":"2026-09-30 19:57:08"},"problem_types":["CWE-362","CWE-362 CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"],"metrics":[{"version":"4.0","source":"info@cert.vde.com","type":"Secondary","score":"7.2","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"7.2","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.2,"baseSeverity":"HIGH","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"}},{"version":"3.1","source":"info@cert.vde.com","type":"Secondary","score":"8.1","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"8.1","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://www.certvde.com/en/advisories/VDE-2026-097/","name":"https://www.certvde.com/en/advisories/VDE-2026-097/","refsource":"info@cert.vde.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-79625","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79625","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"CODESYS","product":"Control RTE (SL)","version":"affected 3.0.0.0 3.5.22.40 semver","platforms":[]},{"source":"CNA","vendor":"CODESYS","product":"Control RTE (for Beckhoff CX) SL","version":"affected 3.0.0.0 3.5.22.40 semver","platforms":[]},{"source":"CNA","vendor":"CODESYS","product":"Control Win (SL)","version":"affected 3.0.0.0 3.5.22.40 semver","platforms":[]},{"source":"CNA","vendor":"CODESYS","product":"Runtime Toolkit","version":"affected 3.0.0.0 3.5.22.40 semver","platforms":[]},{"source":"CNA","vendor":"CODESYS","product":"Safety SIL2","version":"affected 3.0.0.0 3.5.22.40 semver","platforms":[]},{"source":"CNA","vendor":"CODESYS","product":"HMI (SL)","version":"affected 3.0.0.0 3.5.22.40 semver","platforms":[]},{"source":"CNA","vendor":"CODESYS","product":"Development System 3","version":"affected 3.0.0.0 3.5.22.40 semver","platforms":[]},{"source":"CNA","vendor":"CODESYS","product":"Control for BeagleBone SL","version":"affected 3.5.0.0 4.23.0.0 semver","platforms":[]},{"source":"CNA","vendor":"CODESYS","product":"Control for emPC-A/iMX6 SL","version":"affected 3.5.0.0 4.23.0.0 semver","platforms":[]},{"source":"CNA","vendor":"CODESYS","product":"Control for IOT2000 SL","version":"affected 3.5.0.0 4.23.0.0 semver","platforms":[]},{"source":"CNA","vendor":"CODESYS","product":"Control for Linux ARM SL","version":"affected 3.5.0.0 4.23.0.0 semver","platforms":[]},{"source":"CNA","vendor":"CODESYS","product":"Control for Linux SL","version":"affected 3.5.0.0 4.23.0.0 semver","platforms":[]},{"source":"CNA","vendor":"CODESYS","product":"Control for PFC100 SL","version":"affected 3.5.0.0 4.23.0.0 semver","platforms":[]},{"source":"CNA","vendor":"CODESYS","product":"Control for PFC200 SL","version":"affected 3.5.0.0 4.23.0.0 semver","platforms":[]},{"source":"CNA","vendor":"CODESYS","product":"Control for PLCnext SL","version":"affected 3.5.0.0 4.23.0.0 semver","platforms":[]},{"source":"CNA","vendor":"CODESYS","product":"Control for Raspberry Pi SL","version":"affected 3.5.0.0 4.23.0.0 semver","platforms":[]},{"source":"CNA","vendor":"CODESYS","product":"Control for WAGO Touch Panels 600 SL","version":"affected 3.5.0.0 4.23.0.0 semver","platforms":[]},{"source":"CNA","vendor":"CODESYS","product":"Virtual Control SL","version":"affected 3.5.0.0 4.23.0.0 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-79625","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-30T13:49:04.420443Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-30T13:49:14.992Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Control RTE (SL)","vendor":"CODESYS","versions":[{"lessThan":"3.5.22.40","status":"affected","version":"3.0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"Control RTE (for Beckhoff CX) SL","vendor":"CODESYS","versions":[{"lessThan":"3.5.22.40","status":"affected","version":"3.0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"Control Win (SL)","vendor":"CODESYS","versions":[{"lessThan":"3.5.22.40","status":"affected","version":"3.0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"Runtime Toolkit","vendor":"CODESYS","versions":[{"lessThan":"3.5.22.40","status":"affected","version":"3.0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"Safety SIL2","vendor":"CODESYS","versions":[{"lessThan":"3.5.22.40","status":"affected","version":"3.0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"HMI (SL)","vendor":"CODESYS","versions":[{"lessThan":"3.5.22.40","status":"affected","version":"3.0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"Development System 3","vendor":"CODESYS","versions":[{"lessThan":"3.5.22.40","status":"affected","version":"3.0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"Control for BeagleBone SL","vendor":"CODESYS","versions":[{"lessThan":"4.23.0.0","status":"affected","version":"3.5.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"Control for emPC-A/iMX6 SL","vendor":"CODESYS","versions":[{"lessThan":"4.23.0.0","status":"affected","version":"3.5.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"Control for IOT2000 SL","vendor":"CODESYS","versions":[{"lessThan":"4.23.0.0","status":"affected","version":"3.5.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"Control for Linux ARM SL","vendor":"CODESYS","versions":[{"lessThan":"4.23.0.0","status":"affected","version":"3.5.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"Control for Linux SL","vendor":"CODESYS","versions":[{"lessThan":"4.23.0.0","status":"affected","version":"3.5.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"Control for PFC100 SL","vendor":"CODESYS","versions":[{"lessThan":"4.23.0.0","status":"affected","version":"3.5.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"Control for PFC200 SL","vendor":"CODESYS","versions":[{"lessThan":"4.23.0.0","status":"affected","version":"3.5.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"Control for PLCnext SL","vendor":"CODESYS","versions":[{"lessThan":"4.23.0.0","status":"affected","version":"3.5.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"Control for Raspberry Pi SL","vendor":"CODESYS","versions":[{"lessThan":"4.23.0.0","status":"affected","version":"3.5.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"Control for WAGO Touch Panels 600 SL","vendor":"CODESYS","versions":[{"lessThan":"4.23.0.0","status":"affected","version":"3.5.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"Virtual Control SL","vendor":"CODESYS","versions":[{"lessThan":"4.23.0.0","status":"affected","version":"3.5.0.0","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.</p>"}],"value":"Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition."}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.2,"baseSeverity":"HIGH","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-362","description":"CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-30T09:23:16.775Z","orgId":"270ccfa6-a436-4e77-922e-914ec3a9685c","shortName":"CERTVDE"},"references":[{"url":"https://www.certvde.com/en/advisories/VDE-2026-097/"}],"source":{"advisory":"VDE-2026-097","defect":["CERT@VDE#642221"],"discovery":"UNKNOWN"},"title":"Improper Synchronization in Monitoring in CODESYS Control Runtime","x_generator":{"engine":"Vulnogram 0.4.0"}}},"cveMetadata":{"assignerOrgId":"270ccfa6-a436-4e77-922e-914ec3a9685c","assignerShortName":"CERTVDE","cveId":"CVE-2026-79625","datePublished":"2026-09-30T09:23:16.775Z","dateReserved":"2026-08-25T08:46:38.207Z","dateUpdated":"2026-09-30T13:49:14.992Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-30 10:17:17","lastModifiedDate":"2026-09-30 19:57:08","problem_types":["CWE-362","CWE-362 CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"],"metrics":{"cvssMetricV40":[{"source":"info@cert.vde.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"info@cert.vde.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-30T13:49:04.420443Z","id":"CVE-2026-79625","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"79625","Ordinal":"1","Title":"Improper Synchronization in Monitoring in CODESYS Control Runtim","CVE":"CVE-2026-79625","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"79625","Ordinal":"1","NoteData":"Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.","Type":"Description","Title":"Improper Synchronization in Monitoring in CODESYS Control Runtim"}]}}}