AI description
CVE-2025-41659 describes a vulnerability within the CODESYS Control runtime system. This flaw permits a low-privileged attacker to remotely access the Public Key Infrastructure (PKI) folder. Once access is gained, the attacker can read and write certificates and their associated keys. This manipulation could lead to the extraction of sensitive data or the acceptance of certificates as trusted. Should certificates be deleted, the system would then default to unencrypted communication.
- Description
- A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates as trusted. Although all services remain available, only unencrypted communication is possible if the certificates are deleted.
- Source
- info@cert.vde.com
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 8.3
- Impact score
- 5.5
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
- Severity
- HIGH
- info@cert.vde.com
- CWE-732
- Hype score
- Not currently trending
Backdooring CODESYS Applications via Vulnerability Chaining #PLC CVE-2025-41658 + CVE-2025-41659 + CVE-2025-41660 https://t.co/Dlm1VsW1gP https://t.co/4OJyigA3VG
@blackorbird
26 Apr 2026
3539 Impressions
10 Retweets
31 Likes
13 Bookmarks
1 Reply
1 Quote
CVE-2025-41659 (CVSS:8.3, HIGH) is Awaiting Analysis. A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and wri..https://t.co/3YzFJfuOzH #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
9 Aug 2025
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-41659 A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sens… https://t.co/EcNPevCnm3
@CVEnew
4 Aug 2025
468 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
CVE-2025-41659 PKI Certificate Access Vulnerability in CODESYS Control Runtime System https://t.co/Iqj5LowXZB
@VulmonFeeds
4 Aug 2025
80 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes