CVE-2026-79625
Received
Received - Intake
Race Condition in Monitoring System Leads to Data Corruption
Vulnerability report for CVE-2026-79625, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-30
Last updated on: 2026-09-30
Assigner: CERT VDE
Description
Description
Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| codesys | control_runtime | to 3.5.22.40 (inc) |
| codesys | development_system | to 3.5.22.40 (inc) |
| codesys | runtime_toolkit | to 3.5.22.40 (inc) |
| codesys | safety_sil2 | to 3.5.22.40 (inc) |
| codesys | control_rte | to 3.5.22.40 (inc) |
| codesys | win | to 3.5.22.40 (inc) |
| codesys | linux | to 3.5.22.40 (inc) |
| codesys | raspberry_pi | to 3.5.22.40 (inc) |
| codesys | plcnext | to 3.5.22.40 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-362 | The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently. |