The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Codesys
Subscribe
|
Codesys Development System 3
Subscribe
Codesys Edge Gateway For Linux
Subscribe
Codesys Edge Gateway For Windows
Subscribe
Codesys Gateway
Subscribe
Codesys Hmi Sl
Subscribe
Codesys Opc Da Server Sl
Subscribe
Codesys Plchandler
Subscribe
Codesys Runtime Toolkit
Subscribe
Development System V3
Subscribe
Edge Gateway For Linux
Subscribe
Gateway
Subscribe
Hmi (sl)
Subscribe
Opc Da Server
Subscribe
Plchandler
Subscribe
Runtime Toolkit
Subscribe
|
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-094/ |
|
History
Wed, 30 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Codesys development System V3
Codesys edge Gateway For Linux Codesys gateway Codesys hmi (sl) Codesys opc Da Server Codesys plchandler Codesys runtime Toolkit |
|
| Vendors & Products |
Codesys development System V3
Codesys edge Gateway For Linux Codesys gateway Codesys hmi (sl) Codesys opc Da Server Codesys plchandler Codesys runtime Toolkit |
Wed, 30 Sep 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity. | |
| Title | Uncontrolled Memory Allocation in CODESYS Gateway Client | |
| First Time appeared |
Codesys
Codesys codesys Development System 3 Codesys codesys Edge Gateway For Linux Codesys codesys Edge Gateway For Windows Codesys codesys Gateway Codesys codesys Hmi Sl Codesys codesys Opc Da Server Sl Codesys codesys Plchandler Codesys codesys Runtime Toolkit |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:2.3:a:codesys:codesys_development_system_3:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_edge_gateway_for_linux:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_edge_gateway_for_windows:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_gateway:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_hmi_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_opc_da_server_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_plchandler:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_runtime_toolkit:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Codesys
Codesys codesys Development System 3 Codesys codesys Edge Gateway For Linux Codesys codesys Edge Gateway For Windows Codesys codesys Gateway Codesys codesys Hmi Sl Codesys codesys Opc Da Server Sl Codesys codesys Plchandler Codesys codesys Runtime Toolkit |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-09-30T15:28:07.834Z
Reserved: 2026-08-20T06:57:08.465Z
Link: CVE-2026-76992
No data.
Status : Deferred
Published: 2026-09-30T11:16:47.283
Modified: 2026-09-30T19:57:08.043
Link: CVE-2026-76992
No data.
OpenCVE Enrichment
Updated: 2026-09-30T20:15:05Z
Weaknesses