CVE-2025-41739
EUVD-2025-19997601.12.2025, 10:16
An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| codesys | plchandler | 3.5.21.0 ≤ 𝑥 < 3.5.21.40 | CNA |
| codesys | plchandler | 4.15.0.0 ≤ 𝑥 < 4.19.0.0 | CNA |
Common Weakness Enumeration