CVE-2025-41659 Information
Aug 05, 2025
cve
Description
A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates as trusted. Although all services remain available only unencrypted communication is possible if the certificates are deleted.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Reference
https://certvde.com/de/advisories/VDE-2025-051
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
LOW
Base Severity
8.3
Related CNNVD
CNNVD-202508-203 (Published: 2025-08-04)
Share on: