CVE-2026-76992
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Summary
The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| CODESYS | Development System 3 | 3.0.0.0 < 3.5.22.40 | affected |
| CODESYS | Gateway | 3.0.0.0 < 3.5.22.40 | affected |
| CODESYS | Edge Gateway for Windows | 3.0.0.0 < 3.5.22.40 | affected |
| CODESYS | HMI (SL) | 3.0.0.0 < 3.5.22.40 | affected |
| CODESYS | OPC DA Server SL | 3.0.0.0 < 3.5.22.40 | affected |
| CODESYS | PLCHandler | 3.0.0.0 < 3.5.22.40 | affected |
| CODESYS | Runtime Toolkit | 3.0.0.0 < 3.5.22.40 | affected |
| CODESYS | Edge Gateway for Linux | 3.15.0.0 < 4.23.0.0 | affected |
Weaknesses
- CWE-770: CWE-770 Allocation of Resources Without Limits or Throttling
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.