Vulnerability Details CVE-2025-41738
An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.4%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2025-41738
-
cpe:2.3:a:codesys:control_for_beaglebone_sl:4.10.0.0
-
cpe:2.3:a:codesys:control_for_beaglebone_sl:4.11.0.0
-
cpe:2.3:a:codesys:control_for_beaglebone_sl:4.8.0.0
-
cpe:2.3:a:codesys:control_for_empc-a/imx6_sl:4.10.0.0
-
cpe:2.3:a:codesys:control_for_empc-a/imx6_sl:4.8.0.0
-
cpe:2.3:a:codesys:control_for_iot2000_sl:4.10.0.0
-
cpe:2.3:a:codesys:control_for_iot2000_sl:4.11.0.0
-
cpe:2.3:a:codesys:control_for_iot2000_sl:4.8.0.0
-
cpe:2.3:a:codesys:control_for_linux_arm_sl:4.11.0.0
-
cpe:2.3:a:codesys:control_for_linux_sl:4.10.0.0
-
cpe:2.3:a:codesys:control_for_linux_sl:4.11.0.0
-
cpe:2.3:a:codesys:control_for_linux_sl:4.8.0.0
-
cpe:2.3:a:codesys:control_for_pfc100_sl:4.10.0.0
-
cpe:2.3:a:codesys:control_for_pfc100_sl:4.11.0.0
-
cpe:2.3:a:codesys:control_for_pfc100_sl:4.8.0.0
-
cpe:2.3:a:codesys:control_for_pfc200_sl:4.10.0.0
-
cpe:2.3:a:codesys:control_for_pfc200_sl:4.11.0.0
-
cpe:2.3:a:codesys:control_for_pfc200_sl:4.8.0.0
-
cpe:2.3:a:codesys:control_for_plcnext_sl:4.10.0.0
-
cpe:2.3:a:codesys:control_for_plcnext_sl:4.11.0.0
-
cpe:2.3:a:codesys:control_for_plcnext_sl:4.8.0.0
-
cpe:2.3:a:codesys:control_for_raspberry_pi_sl:4.10.0.0
-
cpe:2.3:a:codesys:control_for_raspberry_pi_sl:4.11.0.0
-
cpe:2.3:a:codesys:control_for_raspberry_pi_sl:4.8.0.0
-
cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:4.10.0.0
-
cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:4.11.0.0
-
cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:4.8.0.0
-
cpe:2.3:a:codesys:control_rte_sl:3.5.19.0
-
cpe:2.3:a:codesys:control_rte_sl:3.5.19.20
-
cpe:2.3:a:codesys:control_rte_sl_(for_beckhoff_cx):3.5.19.0
-
cpe:2.3:a:codesys:control_rte_sl_(for_beckhoff_cx):3.5.19.20
-
cpe:2.3:a:codesys:control_win_sl:3.5.19.0
-
cpe:2.3:a:codesys:control_win_sl:3.5.19.20
-
cpe:2.3:a:codesys:hmi_sl:3.5.19.0
-
cpe:2.3:a:codesys:remote_target_visu:*
-
cpe:2.3:a:codesys:runtime_toolkit:3.5.19.0
-
cpe:2.3:a:codesys:runtime_toolkit:3.5.19.50
-
cpe:2.3:a:codesys:virtual_control_sl:*