Critical CODESYS V3 RCE Flaws Threaten Industrial PLCs Worldwide

TL;DR Summary
Millions of programmable logic controllers (PLCs) used in industrial environments worldwide are vulnerable to 15 high-severity vulnerabilities in the CODESYS V3 software development kit, which could allow remote code execution (RCE) and denial of service (DoS) attacks. Over 500 device manufacturers use CODESYS V3, and Microsoft researchers discovered the flaws and reported them to CODESYS in September 2022. While security updates have been released, the nature of these devices makes patching challenging, so Microsoft has raised awareness of the risks and advises upgrading to the latest version of CODESYS V3 and disconnecting PLCs from the internet.
Topics:technology#codesys-v3#cybersecurity#industrial-security#plcs#remote-code-execution#vulnerabilities
- Industrial PLCs worldwide impacted by CODESYS V3 RCE flaws BleepingComputer
- 16 New CODESYS SDK Flaws Expose OT Environments to Remote Attacks The Hacker News
- Microsoft finds vulnerabilities it says could be used to shut down power plants Ars Technica
- Microsoft Discloses Codesys Flaws Allowing Shutdown of Industrial Operations, Spying SecurityWeek
- Microsoft: Codesys PLC bugs could be exploited to 'shut down power plants' The Register
- View Full Coverage on Google News
Reading Insights
Total Reads
0
Unique Readers
11
Time Saved
2 min
vs 3 min read
Condensed
81%
498 → 96 words
Want the full story? Read the original article
Read on BleepingComputer