ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

11 critical security flaws identified in CoDeSys Automation Software

Chinese cybersecurity firm NSFOCUS has discovered 11 critical security flaws in the CoDeSys Automation Software, used by automation specialists as a development environment for programmable logic controller applications (PLCs).

 

The security experts warned that the flaws could be used to launch denial-of-service (DoS) attacks or gain unauthorized access to corporate resources.

 

According to NSFOCUS, these flaws are easy to exploit and potentially lead to arbitrary code execution, sensitive data leakage, and PLCs going into a serious fault state. These vulnerabilities could expose industrial production to stagnation, equipment damage, etc., when combined with industrial scenarios on the field.

 

NSFOCUS asserted that between September 2021 and January 2022, it first informed CoDeSys of the flaws. Then, last week, CoDeSys released a patch covered in two different advisories. Two of the 11 flaws discovered by NSFOCUS are classified as Critical, seven as High, and two as Medium in the company’s advisories.

 

The common vulnerability scoring system (CVSS) for the two critical flaws mentioned in the document is 9.8. The first is using cleartext passwords to authenticate users before PLC operations. On the other hand, the second describes how the CoDeSys Control runtime system does not by default activate password protection.

 

By taking advantage of these two vulnerabilities, bad actors may be able to take over the target PLC device or download a malicious project to a PLC and then run arbitrary code. The other flaws that NSFOCUS found may primarily result in DoS situations. Although CoDeSys have patched all vulnerabilities, many vendors who use the CoDeSys V2 runtime have not yet updated their programs to the most recent version, according to NSFOCUS.

 

Notably, CoDeSys software has previously been found to contain vulnerabilities. The software discovered a backdoor that allowed anyone with the right syntax to access the command shell ten years ago.

 


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543