Логотип exploitDog
bind:CVE-2025-41659
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-41659

Количество 3

Количество 3

nvd логотип

CVE-2025-41659

6 месяцев назад

A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates as trusted. Although all services remain available, only unencrypted communication is possible if the certificates are deleted.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-x97q-fjxx-pvxm

6 месяцев назад

A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates as trusted. Although all services remain available, only unencrypted communication is possible if the certificates are deleted.

CVSS3: 8.3
EPSS: Низкий
fstec логотип

BDU:2026-00081

6 месяцев назад

Уязвимость программных продуктов CODESYS, связанная с неверным назначением разрешений для критического ресурса, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 8.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-41659

A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates as trusted. Although all services remain available, only unencrypted communication is possible if the certificates are deleted.

CVSS3: 8.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-x97q-fjxx-pvxm

A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates as trusted. Although all services remain available, only unencrypted communication is possible if the certificates are deleted.

CVSS3: 8.3
0%
Низкий
6 месяцев назад
fstec логотип
BDU:2026-00081

Уязвимость программных продуктов CODESYS, связанная с неверным назначением разрешений для критического ресурса, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 8.3
0%
Низкий
6 месяцев назад

Уязвимостей на страницу