Vulnerability Details CVE-2025-41700
An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 11.3%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2025-41700
-
cpe:2.3:a:codesys:codesys:-
-
cpe:2.3:a:codesys:codesys:1.1.9.22
-
cpe:2.3:a:codesys:codesys:2.3
-
cpe:2.3:a:codesys:codesys:2.3.9.61
-
cpe:2.3:a:codesys:codesys:3.5.10.0
-
cpe:2.3:a:codesys:codesys:3.5.10.10
-
cpe:2.3:a:codesys:codesys:3.5.10.20
-
cpe:2.3:a:codesys:codesys:3.5.10.30
-
cpe:2.3:a:codesys:codesys:3.5.10.40
-
cpe:2.3:a:codesys:codesys:3.5.10.50
-
cpe:2.3:a:codesys:codesys:3.5.10.60
-
cpe:2.3:a:codesys:codesys:3.5.10.70
-
cpe:2.3:a:codesys:codesys:3.5.11.0
-
cpe:2.3:a:codesys:codesys:3.5.11.10
-
cpe:2.3:a:codesys:codesys:3.5.11.20
-
cpe:2.3:a:codesys:codesys:3.5.11.30
-
cpe:2.3:a:codesys:codesys:3.5.11.40
-
cpe:2.3:a:codesys:codesys:3.5.11.50
-
cpe:2.3:a:codesys:codesys:3.5.11.60
-
cpe:2.3:a:codesys:codesys:3.5.12.0
-
cpe:2.3:a:codesys:codesys:3.5.12.10
-
cpe:2.3:a:codesys:codesys:3.5.12.20
-
cpe:2.3:a:codesys:codesys:3.5.12.30
-
cpe:2.3:a:codesys:codesys:3.5.12.40
-
cpe:2.3:a:codesys:codesys:3.5.12.50
-
cpe:2.3:a:codesys:codesys:3.5.12.60
-
cpe:2.3:a:codesys:codesys:3.5.12.70
-
cpe:2.3:a:codesys:codesys:3.5.13.0
-
cpe:2.3:a:codesys:codesys:3.5.13.10
-
cpe:2.3:a:codesys:codesys:3.5.13.2
-
cpe:2.3:a:codesys:codesys:3.5.13.20
-
cpe:2.3:a:codesys:codesys:3.5.13.30
-
cpe:2.3:a:codesys:codesys:3.5.13.40
-
cpe:2.3:a:codesys:codesys:3.5.14.10
-
cpe:2.3:a:codesys:codesys:3.5.14.20
-
cpe:2.3:a:codesys:codesys:3.5.14.30
-
cpe:2.3:a:codesys:codesys:3.5.14.40
-
cpe:2.3:a:codesys:codesys:3.5.15.0
-
cpe:2.3:a:codesys:codesys:3.5.15.10
-
cpe:2.3:a:codesys:codesys:3.5.15.20
-
cpe:2.3:a:codesys:codesys:3.5.15.30
-
cpe:2.3:a:codesys:codesys:3.5.15.40
-
cpe:2.3:a:codesys:codesys:3.5.15.50
-
cpe:2.3:a:codesys:codesys:3.5.16.0
-
cpe:2.3:a:codesys:codesys:3.5.16.10
-
cpe:2.3:a:codesys:codesys:3.5.16.20
-
cpe:2.3:a:codesys:codesys:3.5.16.30
-
cpe:2.3:a:codesys:codesys:3.5.16.40
-
cpe:2.3:a:codesys:codesys:3.5.16.50
-
cpe:2.3:a:codesys:codesys:3.5.17.0
-
cpe:2.3:a:codesys:codesys:3.5.9.40
-
cpe:2.3:a:codesys:codesys:3.5.9.50
-
cpe:2.3:a:codesys:codesys:3.5.9.60
-
cpe:2.3:a:codesys:codesys:3.5.9.70
-
cpe:2.3:a:codesys:codesys:3.5.9.80