Sensitive File Exposure in CODESYS Runtime Toolkit Products
CVE-2025-41658

5.5MEDIUM

What is CVE-2025-41658?

The CODESYS Runtime Toolkit may inadvertently expose sensitive files to local low-privileged operating system users due to improper default file permissions. This vulnerability could lead to unauthorized access to sensitive information, potentially compromising system integrity and confidentiality. It is essential for users of CODESYS products to review their file permission settings and implement necessary security measures to mitigate these risks.

Affected Version(s)

Control for BeagleBone SL 0.0.0.0 < 4.16.0.0

Control for emPC-A/iMX6 SL 0.0.0.0 < 4.16.0.0

Control for IOT2000 SL 0.0.0.0 < 4.16.0.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Luca Borzacchiello from Nozomi Networks
.