The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited out-of-bounds write. An unauthenticated remote attacker can exploit this flaw to cause a denial of service via a system crash on the affected device.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-057/ |
|
History
Tue, 26 May 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited out-of-bounds write. An unauthenticated remote attacker can exploit this flaw to cause a denial of service via a system crash on the affected device. | |
| Title | Out-of-bounds Write in CODESYS Control | |
| First Time appeared |
Codesys
Codesys codesys Control For Beaglebone Sl Codesys codesys Control For Empc A Imx6 Sl Codesys codesys Control For Iot2000 Sl Codesys codesys Control For Linux Arm Sl Codesys codesys Control For Linux Sl Codesys codesys Control For Pfc100 Sl Codesys codesys Control For Pfc200 Sl Codesys codesys Control For Plcnext Sl Codesys codesys Control For Raspberry Pi Sl Codesys codesys Control For Wago Touch Panels 600 Sl Codesys codesys Control Rte For Beckhoff Cx Sl Codesys codesys Control Rte Sl Codesys codesys Control Win Sl Codesys codesys Hmi Sl Codesys codesys Runtime Toolkit Codesys codesys Virtual Control Sl |
|
| Weaknesses | CWE-1284 | |
| CPEs | cpe:2.3:a:codesys:codesys_control_for_beaglebone_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_control_for_empc_a_imx6_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_control_for_iot2000_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_control_for_linux_arm_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_control_for_linux_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_control_for_pfc100_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_control_for_pfc200_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_control_for_plcnext_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_control_for_raspberry_pi_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_control_rte_for_beckhoff_cx_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_control_rte_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_control_win_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_hmi_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_runtime_toolkit:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:codesys_virtual_control_sl:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Codesys
Codesys codesys Control For Beaglebone Sl Codesys codesys Control For Empc A Imx6 Sl Codesys codesys Control For Iot2000 Sl Codesys codesys Control For Linux Arm Sl Codesys codesys Control For Linux Sl Codesys codesys Control For Pfc100 Sl Codesys codesys Control For Pfc200 Sl Codesys codesys Control For Plcnext Sl Codesys codesys Control For Raspberry Pi Sl Codesys codesys Control For Wago Touch Panels 600 Sl Codesys codesys Control Rte For Beckhoff Cx Sl Codesys codesys Control Rte Sl Codesys codesys Control Win Sl Codesys codesys Hmi Sl Codesys codesys Runtime Toolkit Codesys codesys Virtual Control Sl |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-05-26T06:49:54.813Z
Reserved: 2026-05-06T17:12:05.142Z
Link: CVE-2026-8047
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-05-26T09:00:12Z