Back to overview

CVE-2026-35226

MEDIUM
6.5
CVSS 3.1
Description
An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in a controlled stop of the PLC application.

Metadata

CVE ID
CVE-2026-35226
State
PUBLISHED
Assigner
CERTVDE
Reserved
2026-04-01 19:54 UTC
Published
2026-07-29 07:05 UTC
Last updated
2026-07-29 07:05 UTC
Primary CWE
CWE-787
CWE-787 Out-of-bounds Write
Vendor / Product
CODESYS / CODESYS PROFINET
Sources
cve.org  ·  NVD

Severity & Metrics

6.5 MEDIUM CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products (1)
VendorProductPlatformVersions
CODESYS CODESYS PROFINET 4.4.0.0 < 4.8.0.0
Weakness (CWE)
CWESourceDescription
CWE-787 cna CWE-787 Out-of-bounds Write
CVSS scores (2)
ScoreSeverityVersionSourceVector
7.1 HIGH 4.0 cna CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
6.5 MEDIUM 3.1 cna CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Back to overview