CVE-2026-35226
Received Received - Intake

Out-of-Bounds Write in CODESYS PROFINET Controller

Vulnerability report for CVE-2026-35226, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-29

Assigner: CERT VDE

Description

An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in a controlled stop of the PLC application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-29
Generated
2026-07-29
AI Q&A
2026-07-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
codesys profinet_controller From 4.4.0.0 (inc) to 4.8.0.0 (inc)
codesys profinet_controller to 4.8.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds write flaw in the CODESYS PROFINET Controller affecting versions 4.4.0.0 to 4.8.0.0. It occurs when invalid PROFINET communication data is processed, causing the CODESYS Control runtime to handle an exception and stop the PLC application in a controlled manner. An unauthenticated attacker on the same network segment can exploit this by sending malformed data, leading to a denial-of-service condition until the PLC is restarted.

Detection Guidance

Monitor network traffic for malformed PROFINET communication data using packet inspection tools like Wireshark. Check CODESYS Control runtime logs for exceptions or controlled stops of the PLC application. Verify if the affected versions (4.4.0.0 to 4.8.0.0) are installed.

Impact Analysis

The vulnerability can cause a denial-of-service condition for the PLC application, stopping its operation until manually restarted. This disrupts industrial processes relying on the PLC, potentially leading to production downtime or safety risks. However, remote code execution is prevented due to the controlled stop mechanism.

Mitigation Strategies

Update CODESYS PROFINET Controller to version 4.8.0.0 or later. Update the PROFINET Controller in the device tree and redeploy the application to the PLC. Obtain updates via the CODESYS Installer, CODESYS Store, or the CODESYS Update area.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-35226. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart