Press release
Positive Technologies helps to fix dangerous vulnerability in CODESYS ICS software
A Positive Technologies application analysis expert studied the CODESYS Runtime System and discovered a high-severity vulnerabilityCODESYS Group has fixed a vulnerability in the ICS software package CODESYS V3 Runtime System detected by Positive Technologies expert Denis Goryushev. CODESYS V3 Runtime System is part of CODESYS, the leading hardware-independent software, which provides a development environment for programming controller applications in accordance with the industrial automation standard IEC 61131-3. The company's products are installed in over 400 industrial companies in more than 10 countries, including Russia.
This high-severity vulnerability (CVE-2021-36764) was discovered in the CODESYS V3 Runtime System software package (version 3.15.9.10). By exploiting it, an attacker can disable the PLC and disrupt the technological process. The vulnerability (NULL Pointer Dereference) was found in the CmpGateway component. An attacker with network access to the industrial controller can send a specially formed TCP packet and interrupt the operation of the PLC. Also, it has been found that this software contains another vulnerability (Local Privilege Escalation), which is currently being reviewed by the vendor.
Artur Akhatov, ICS Security Analyst, Positive Technologies, said: "CODESYS products are widely used all over the world, including in Russia. One of our partners uses them to create automatic fire-fighting systems for power plants. If criminals exploit this vulnerability to disrupt the operation of the fire extinguishing system, it may result in huge losses in case of a fire (for example, if the fire reaches the turbine shop)."
Denis Goryushev, Application Analysis Specialist, Positive Technologies, commented: "The investigated version has been publicly available for quite a long time—it is strange that this vulnerability remained unnoticed until now. It is a simple logical error that occurs because there is no verification of the transmitted values: you can send a specially crafted request controlling the connection, which will lead to a zero address and a denial of service."
The vulnerability was discovered in March, and in just four months, CODESYS released a patch. To fix the vulnerability, install a new software version available on the official CODESYS website. Signs of penetration (for example, if an update cannot be installed) can be detected using solutions for continuous information security monitoring and ICS incident management, such as PT Industrial Security Incident Manager.
CONTACT:
Paula Dunne
CONTOS DUNNE COMMUNICATIONS
+1-408-893-8750 (m)
+1-408-776-1400 (o)
paula@contosdunne.com
8 Preobrazhenskaya Square, Moscow, 107061
About Positive Technologies
Positive Technologies is a leading global provider of enterprise security solutions for vulnerability and compliance management, incident and threat analysis, and application protection. Commitment to clients and research has earned Positive Technologies a reputation as one of the foremost authorities on Industrial Control System, Banking, Telecom, Web Application, and ERP security, supported by recognition from the analyst community.
ptsecurity.com, facebook.com/PositiveTechnologies, facebook.com/PHDays.
This release was published on openPR.
Permanent link to this press release:
Copy
Please set a link in the press area of your homepage to this press release on openPR. openPR disclaims liability for any content contained in this release.
You can edit or delete your press release Positive Technologies helps to fix dangerous vulnerability in CODESYS ICS software here
News-ID: 2362401 • Views: …
More Releases from Positive Technologies

Positive Technologies Report Examines the Evolution and Current Threat of Rootki …
Difficult and Costly to Create, These Malicious Programs That Hide the Presence of Malware Target Governments and Research Institutes, and Are Here to Stay
November 3, 2021 – In a new report, Positive Technologies analyzes this past decade's most infamous families of rootkits—programs that hide the presence of malicious software or traces of intrusion in victim systems. The study finds that the majority of rootkits are used by APT…

New Report from Positive Technologies Finds Ransomware Attacks Have Reached ‘S …
September 22, 2021 – Ransomware attacks have reached ‘stratospheric’ levels, now accounting for 69% of all attacks involving malware. That is among the most disturbing finding in “Cybersecurity Threatscape: Q2 2021,” the latest report from security specialist Positive Technologies. The research also reveals that the volume of attacks on governmental institutions in particular soared from 12% in Q1 2021 to 20% in Q2. And the company’s Expert Security Center (PT…
More Releases for CODESYS
Still struggling with setup? ODOT Automation's new video guide shows how to pair …
To help engineers simplify complex debugging and accelerate project deployment, Odot [https://www.odotautomation.com/odot/] Automation Systems Co., Ltd. has released a series of professional and detailed product operation tutorials designed to help you master the application of ODOT products. This video focuses on the pairing operation of the B2341 and BN8031.
By watching this guide, you will learn:
* Discover devices & configure modulesSeamlessly bridge IO Config setup to Codesys [https://www.odotautomation.com/codesys/] project deployment…
Motion Control Software Market Growth 2022 |ABB, Moog, National Instruments, Phy …
Worldwide Market Reports has announced the addition of the “Global Motion Control Software Market Size Status and Forecast 2022”, The report classifies the global Motion Control Software Market in a precise manner to offer detailed insights about the aspects responsible for augmenting as well as restraining market growth.
This report studies the global Motion Control Software market, analyzes and researches the Motion Control Software development status and forecast in United…
Global Motion Control Software Market 2017 Predictable To Witness Sustainable Ev …
This market research report on the global motion control software market is an all-inclusive study of the business sectors up-to-date frameworks, industry enrichment drivers, and manacles. It provides futuristic market prospects in terms of the upcoming years. The report contains all the necessary veritable of most recent innovations, such as Porter's five force model analysis and advanced profiles of elite industry participants. The report additionally drafts a survey of minor…
The New EHV+ Series from Hitachi
The New Hitachi and CoDeSys – a strong connection
Düsseldorf, November 2012. The new EHV+ series consists of two CPUs with memory capacities of 512 or 2048 kilobytes. Thanks to the onboard Ethernet interface, the CPUs are compatible with a variety of open networks. Alongside CoDeSys V3.4 SP4 HF1, the EHV+ series offers a wide range of precise, digital, analog, remote I/O, and positioning and temperature measurement modules. In addition…
Announcing a new and innovative HMI software More productivity. More value
Exor announced his new HMI software suite JMobile. A new innovative HMI software platform, flexible, powerful and intuitive.
It’s a suite of software components that provides solutions for connecting equipment and visualizing data. JMobile is a software suite designed to offer a complete HMI solution. Thanks to its client server architecture it is possible to create a seamless data transfers from field level up to system management layers. Centralized collected…
Janz expand emPC family with ATOM Processor
Janz Automationssysteme AG has expanded their embedded PC family with Intel’s new series of low power ATOM Processors. The new emPC-M series controllers are powered by Intel Atom N270 Processors at up to 1.6 GHz clockspeed. The emPC-MN270 can be used as a fanless system due to its low power consumption of max. 14 W. A preinstalled IEC 61131-3 Soft PLC system is also available, making the emPC-M series a…