Skip to content
Threat Feed
medium advisory

Multiple Vulnerabilities in CODESYS Control Runtime and Gateway

Multiple vulnerabilities in CODESYS Control Runtime and Gateway Client allow a remote attacker to manipulate data or cause a denial-of-service condition.

CVE search metadata

CVE search record: CVE-2024-44336. Severity: medium. CVSS: 5.3. EPSS: 0.30%. KEV: no. Product: CODESYS Control Runtime, CODESYS Gateway Client. Brief: Multiple Vulnerabilities in CODESYS Control Runtime and Gateway. Brief link: https://feed.craftedsignal.io/briefs/2026-10-codesys-vulnerabilities/

CVE search record: CVE-2024-44337. Severity: medium. CVSS: 5.1. EPSS: 0.51%. KEV: no. Product: CODESYS Control Runtime, CODESYS Gateway Client. Brief: Multiple Vulnerabilities in CODESYS Control Runtime and Gateway. Brief link: https://feed.craftedsignal.io/briefs/2026-10-codesys-vulnerabilities/

CVE search record: CVE-2024-44340. Severity: high. CVSS: 8.8. EPSS: 1.79%. KEV: no. Product: CODESYS Control Runtime, CODESYS Gateway Client. Brief: Multiple Vulnerabilities in CODESYS Control Runtime and Gateway. Brief link: https://feed.craftedsignal.io/briefs/2026-10-codesys-vulnerabilities/

CVE search record: CVE-2024-44341. Severity: critical. CVSS: 9.8. EPSS: 1.83%. KEV: no. Product: CODESYS Control Runtime, CODESYS Gateway Client. Brief: Multiple Vulnerabilities in CODESYS Control Runtime and Gateway. Brief link: https://feed.craftedsignal.io/briefs/2026-10-codesys-vulnerabilities/

The BSI has released an advisory regarding multiple vulnerabilities identified in CODESYS Control Runtime and Gateway Client components. These flaws, tracked under CVE-2024-44336 through CVE-2024-44344, pose a significant risk to industrial environments where these components are deployed. Exploitation of these vulnerabilities may allow an unauthenticated or remote attacker to manipulate process data or induce a denial-of-service (DoS) condition, potentially leading to operational disruption of industrial control systems. As these components often operate in critical infrastructure, defenders must prioritize the assessment of their exposure and apply vendor-provided patches.

Impact

The affected vulnerabilities impact organizations utilizing CODESYS industrial automation software. Successful exploitation could result in the unauthorized modification of process data or complete service unavailability, necessitating emergency maintenance in critical production environments.

Recommendation

Prioritize the identification of all instances of CODESYS Control Runtime and Gateway Client within the enterprise OT environment. Apply security updates provided by CODESYS immediately to mitigate the risks associated with CVE-2024-44336, CVE-2024-44337, CVE-2024-44338, CVE-2024-44339, CVE-2024-44340, CVE-2024-44341, CVE-2024-44342, CVE-2024-44343, and CVE-2024-44344. Ensure internal firewalls restrict access to industrial control interfaces to authorized engineering stations only.

Mitigations

Patch CODESYS Control Runtime and Gateway Client

immediate IT Operations

CVE-2024-44336 through CVE-2024-44344