Access Synchronization Flaw in Monitoring Functionality of Affected Vendor's Product
CVE-2026-79625

7.2HIGH

Key Information:

Vendor

Codesys

Vendor
CVE Published:
30 September 2026

What is CVE-2026-79625?

The vulnerability allows for improper synchronization in monitoring functionalities, leading to potential incorrect reads or writes during concurrent client requests. This issue poses risks such as data corruption and possible denial-of-service scenarios, allowing an authenticated remote attacker with monitoring access to exploit it and disrupt service.

Affected Version(s)

Control for BeagleBone SL 3.5.0.0 < 4.23.0.0

Control for emPC-A/iMX6 SL 3.5.0.0 < 4.23.0.0

Control for IOT2000 SL 3.5.0.0 < 4.23.0.0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.