{
  "document": {
    "acknowledgments": [
      {
        "organization": "CERT@VDE",
        "summary": "coordination",
        "urls": [
          "https://www.certvde.com"
        ]
      },
      {
        "organization": "Delta Electronics Inc.",
        "summary": "reporting"
      }
    ],
    "aggregate_severity": {
      "namespace": "https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale",
      "text": "High"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-GB",
    "notes": [
      {
        "category": "summary",
        "text": "The CODESYS Gateway Client (CmpGatewayClient) is used by various CODESYS products to establish PLC communication via the CODESYS Gateway.\n\nDue to missing limits on memory allocations derived from a size field in a gateway response, a malicious gateway can cause excessive memory consumption in the client, resulting in a denial-of-service condition.\n\nThe vulnerability can be exploited when an affected product connects to an attacker-controlled gateway.",
        "title": "Summary"
      },
      {
        "category": "description",
        "text": "Successful exploitation may result in excessive memory consumption, leading to a denial-of-service condition in the affected client.",
        "title": "Impact"
      },
      {
        "category": "description",
        "text": "Update the following products to version 3.5.22.40. \n* CODESYS Development System 3\n* CODESYS Gateway \n* CODESYS Edge Gateway for Windows\n* CODESYS HMI (SL)\n* CODESYS OPC DA Server SL\n* CODESYS PLCHandler\n* CODESYS Runtime Toolkit\n\nUpdate the following product to version 4.23.0.0. The release of this version is expected in Q4 2026. \n* CODESYS Edge Gateway for Linux\n\nThe CODESYS Development System and the products available as CODESYS add-ons can be downloaded and installed directly with the CODESYS Installer or be downloaded from the CODESYS Store. Alternatively, as well as for all other products, you will find further information on obtaining the software update in the CODESYS Update area https://www.codesys.com/download/.",
        "title": "Remediation"
      },
      {
        "category": "general",
        "text": "As part of a security strategy, CODESYS GmbH strongly recommends at least the following best-practice\ndefense measures:\n\n* Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside\n* Use firewalls to protect and separate the control system network from other networks\n* Activate and apply user management and password features\n* Limit the access to both development and control system by physical means, operating system features, etc.\n* Use encrypted communication links\n* Use VPN (Virtual Private Networks) tunnels if remote access is required\n* Protect both development and control system by using up to date virus detecting solutions\n\nFor more information and general recommendations for protecting machines and plants, see also the\nCODESYS Security Whitepaper [here.](https://www.customers.codesys.com/fileadmin/data/customers/security/CODESYS-Security-Whitepaper.pdf)",
        "title": "General Recommendation"
      },
      {
        "category": "legal_disclaimer",
        "text": "CODESYS GmbH assumes no liability whatsoever for indirect, collateral, accidental or consequential losses\nthat occur by the distribution and/or use of this document or any losses in connection with the distribution and/or use of this document. All information published in this document is provided on good faith by CODESYS GmbH.\nInsofar as permissible by law, however, none of this information shall establish any guarantee, commitment or\nliability on the part of CODESYS GmbH.\n\nNote: Not all CODESYS features are available in all territories. For more information on geographic restrictions,\nplease contact sales@codesys.com.",
        "title": "Disclaimer"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "security@codesys.com",
      "name": "CODESYS GmbH",
      "namespace": "https://www.codesys.com"
    },
    "references": [
      {
        "category": "external",
        "summary": "CERT@VDE Security Advisories for CODESYS GmbH",
        "url": "https://www.certvde.com/en/advisories/vendor/codesys"
      },
      {
        "category": "self",
        "summary": "Advisory2026-11_VDE-2026-094: CODESYS Gateway Client - Uncontrolled Memory Allocation - HTML",
        "url": "https://www.certvde.com/en/advisories/VDE-2026-094/"
      },
      {
        "category": "self",
        "summary": "Advisory2026-11_VDE-2026-094: CODESYS Gateway Client - Uncontrolled Memory Allocation - CSAF",
        "url": "https://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2026/advisory2026-11_vde-2026-094.json"
      },
      {
        "category": "external",
        "summary": "CODESYS Security Advisories",
        "url": "https://www.codesys.com/security/security-reports.html"
      },
      {
        "category": "self",
        "summary": "Advisory2026-11_VDE-2026-094: CODESYS Gateway Client - Uncontrolled Memory Allocation - PDF",
        "url": "https://api-www.codesys.com/fileadmin/user_upload/CODESYS_Group/Ecosystem/Up-to-Date/Security/Security-Advisories/Advisory2026-11_CDS-98296.pdf"
      }
    ],
    "title": "CODESYS Gateway Client - Uncontrolled Memory Allocation",
    "tracking": {
      "aliases": [
        "VDE-2026-094",
        "CODESYS Security Advisory 2026-11"
      ],
      "current_release_date": "2026-09-30T10:00:00.000Z",
      "generator": {
        "date": "2026-09-21T14:15:15.425Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.6.12"
        }
      },
      "id": "Advisory2026-11_VDE-2026-094",
      "initial_release_date": "2026-09-30T10:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-09-30T10:00:00.000Z",
          "number": "1.0.0",
          "summary": "Initial revision."
        }
      ],
      "status": "final",
      "version": "1.0.0"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:generic/>=3.0.0.0|<3.5.22.40",
                    "product": {
                      "name": "CODESYS Development System 3 3.0.0.0<3.5.22.40",
                      "product_id": "CSAFPID-51001",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:codesys:codesys_development_system_3:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "3.5.22.40",
                    "product": {
                      "name": "CODESYS Development System 3 3.5.22.40",
                      "product_id": "CSAFPID-52001",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:codesys:codesys_development_system_3:3.5.22.40:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "CODESYS Development System 3"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:generic/>=3.0.0.0|<3.5.22.40",
                    "product": {
                      "name": "CODESYS Gateway 3.0.0.0<3.5.22.40",
                      "product_id": "CSAFPID-51002",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:codesys:codesys_gateway:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "3.5.22.40",
                    "product": {
                      "name": "CODESYS Gateway 3.5.22.40",
                      "product_id": "CSAFPID-52002",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:codesys:codesys_gateway:3.5.22.40:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "CODESYS Gateway "
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:generic/>=3.0.0.0|<3.5.22.40",
                    "product": {
                      "name": "CODESYS Edge Gateway for Windows 3.0.0.0<3.5.22.40",
                      "product_id": "CSAFPID-51003",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:codesys:codesys_edge_gateway_for_windows:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "3.5.22.40",
                    "product": {
                      "name": "CODESYS Edge Gateway for Windows 3.5.22.40",
                      "product_id": "CSAFPID-52003",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:codesys:codesys_edge_gateway_for_windows:3.5.22.40:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "CODESYS Edge Gateway for Windows"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:generic/>=3.0.0.0|<3.5.22.40",
                    "product": {
                      "name": "CODESYS HMI (SL) 3.0.0.0<3.5.22.40",
                      "product_id": "CSAFPID-51004",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:codesys:codesys_hmi_sl:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "3.5.22.40",
                    "product": {
                      "name": "CODESYS HMI (SL) 3.5.22.40",
                      "product_id": "CSAFPID-52004",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:codesys:codesys_hmi_sl:3.5.22.40:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "CODESYS HMI (SL)"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:generic/>=3.0.0.0|<3.5.22.40",
                    "product": {
                      "name": "CODESYS OPC DA Server SL 3.0.0.0<3.5.22.40",
                      "product_id": "CSAFPID-51005",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:codesys:codesys_opc_da_server_sl:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "3.5.22.40",
                    "product": {
                      "name": "CODESYS OPC DA Server SL 3.5.22.40",
                      "product_id": "CSAFPID-52005",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:codesys:codesys_opc_da_server_sl:3.5.22.40:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "CODESYS OPC DA Server SL"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:generic/>=3.0.0.0|<3.5.22.40",
                    "product": {
                      "name": "CODESYS PLCHandler 3.0.0.0<3.5.22.40",
                      "product_id": "CSAFPID-51006",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:codesys:codesys_plchandler:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "3.5.22.40",
                    "product": {
                      "name": "CODESYS PLCHandler 3.5.22.40",
                      "product_id": "CSAFPID-52006",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:codesys:codesys_plchandler:3.5.22.40:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "CODESYS PLCHandler"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:generic/>=3.0.0.0|<3.5.22.40",
                    "product": {
                      "name": "CODESYS Runtime Toolkit 3.0.0.0<3.5.22.40",
                      "product_id": "CSAFPID-51007",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:codesys:codesys_runtime_toolkit:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "3.5.22.40",
                    "product": {
                      "name": "CODESYS Runtime Toolkit 3.5.22.40",
                      "product_id": "CSAFPID-52007",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:codesys:codesys_runtime_toolkit:3.5.22.40:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "CODESYS Runtime Toolkit"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:generic/>=3.15.0.0|<4.23.0.0",
                    "product": {
                      "name": "CODESYS Edge Gateway for Linux 3.15.0.0<4.23.0.0",
                      "product_id": "CSAFPID-51008",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:codesys:codesys_edge_gateway_for_linux:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "4.23.0.0",
                    "product": {
                      "name": "CODESYS Edge Gateway for Linux 4.23.0.0",
                      "product_id": "CSAFPID-52008",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:codesys:codesys_edge_gateway_for_linux:4.23.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "CODESYS Edge Gateway for Linux"
              }
            ],
            "category": "product_family",
            "name": "Software"
          }
        ],
        "category": "vendor",
        "name": "CODESYS"
      }
    ],
    "product_groups": [
      {
        "group_id": "CSAFGID-1001",
        "product_ids": [
          "CSAFPID-51001",
          "CSAFPID-51002",
          "CSAFPID-51003",
          "CSAFPID-51004",
          "CSAFPID-51005",
          "CSAFPID-51006",
          "CSAFPID-51007"
        ],
        "summary": "Affected products v3.5.x."
      },
      {
        "group_id": "CSAFGID-2001",
        "product_ids": [
          "CSAFPID-52001",
          "CSAFPID-52002",
          "CSAFPID-52003",
          "CSAFPID-52004",
          "CSAFPID-52005",
          "CSAFPID-52006",
          "CSAFPID-52007"
        ],
        "summary": "Fixed products v3.5.x."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-76992",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "notes": [
        {
          "audience": "all",
          "category": "description",
          "text": "The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-52001",
          "CSAFPID-52002",
          "CSAFPID-52003",
          "CSAFPID-52004",
          "CSAFPID-52005",
          "CSAFPID-52006",
          "CSAFPID-52007",
          "CSAFPID-52008"
        ],
        "known_affected": [
          "CSAFPID-51001",
          "CSAFPID-51002",
          "CSAFPID-51003",
          "CSAFPID-51004",
          "CSAFPID-51005",
          "CSAFPID-51006",
          "CSAFPID-51007",
          "CSAFPID-51008"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N - 8.7 / High",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Update the following products to version 3.5.22.40. \n* CODESYS Development System 3\n* CODESYS Gateway \n* CODESYS Edge Gateway for Windows\n* CODESYS HMI (SL)\n* CODESYS OPC DA Server SL\n* CODESYS PLCHandler\n* CODESYS Runtime Toolkit\n\nThe CODESYS Development System and the products available as CODESYS add-ons can be downloaded and installed directly with the CODESYS Installer or be downloaded from the CODESYS Store. Alternatively, as well as for all other products, you will find further information on obtaining the software update in the CODESYS Update area https://www.codesys.com/download/. ",
          "group_ids": [
            "CSAFGID-1001"
          ]
        },
        {
          "category": "none_available",
          "details": "Update the following product to version 4.23.0.0. The release of this version is expected in Q4 2026. \n* CODESYS Edge Gateway for Linux\n\nThe CODESYS Development System and the products available as CODESYS add-ons can be downloaded and installed directly with the CODESYS Installer or be downloaded from the CODESYS Store. Alternatively, as well as for all other products, you will find further information on obtaining the software update in the CODESYS Update area https://www.codesys.com/download/. ",
          "product_ids": [
            "CSAFPID-51008"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "environmentalScore": 7.5,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 7.5,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-51001",
            "CSAFPID-51002",
            "CSAFPID-51003",
            "CSAFPID-51004",
            "CSAFPID-51005",
            "CSAFPID-51006",
            "CSAFPID-51007",
            "CSAFPID-51008"
          ]
        }
      ],
      "title": "Uncontrolled Memory Allocation in CODESYS Gateway Client"
    }
  ]
}