
Critical CODESYS V3 RCE Flaws Threaten Industrial PLCs Worldwide
Millions of programmable logic controllers (PLCs) used in industrial environments worldwide are vulnerable to 15 high-severity vulnerabilities in the CODESYS V3 software development kit, which could allow remote code execution (RCE) and denial of service (DoS) attacks. Over 500 device manufacturers use CODESYS V3, and Microsoft researchers discovered the flaws and reported them to CODESYS in September 2022. While security updates have been released, the nature of these devices makes patching challenging, so Microsoft has raised awareness of the risks and advises upgrading to the latest version of CODESYS V3 and disconnecting PLCs from the internet.