Multiple Vulnerabilities in CODESYS Control Runtime and Gateway
Multiple vulnerabilities in CODESYS Control Runtime and Gateway Client allow a remote attacker to manipulate data or cause a denial-of-service condition.
CVE search metadata
CVE search record: CVE-2024-44336. Severity: medium. CVSS: 5.3. EPSS: 0.30%. KEV: no. Product: CODESYS Control Runtime, CODESYS Gateway Client. Brief: Multiple Vulnerabilities in CODESYS Control Runtime and Gateway. Brief link: https://feed.craftedsignal.io/briefs/2026-10-codesys-vulnerabilities/
CVE search record: CVE-2024-44337. Severity: medium. CVSS: 5.1. EPSS: 0.51%. KEV: no. Product: CODESYS Control Runtime, CODESYS Gateway Client. Brief: Multiple Vulnerabilities in CODESYS Control Runtime and Gateway. Brief link: https://feed.craftedsignal.io/briefs/2026-10-codesys-vulnerabilities/
CVE search record: CVE-2024-44340. Severity: high. CVSS: 8.8. EPSS: 1.79%. KEV: no. Product: CODESYS Control Runtime, CODESYS Gateway Client. Brief: Multiple Vulnerabilities in CODESYS Control Runtime and Gateway. Brief link: https://feed.craftedsignal.io/briefs/2026-10-codesys-vulnerabilities/
CVE search record: CVE-2024-44341. Severity: critical. CVSS: 9.8. EPSS: 1.83%. KEV: no. Product: CODESYS Control Runtime, CODESYS Gateway Client. Brief: Multiple Vulnerabilities in CODESYS Control Runtime and Gateway. Brief link: https://feed.craftedsignal.io/briefs/2026-10-codesys-vulnerabilities/
The BSI has released an advisory regarding multiple vulnerabilities identified in CODESYS Control Runtime and Gateway Client components. These flaws, tracked under CVE-2024-44336 through CVE-2024-44344, pose a significant risk to industrial environments where these components are deployed. Exploitation of these vulnerabilities may allow an unauthenticated or remote attacker to manipulate process data or induce a denial-of-service (DoS) condition, potentially leading to operational disruption of industrial control systems. As these components often operate in critical infrastructure, defenders must prioritize the assessment of their exposure and apply vendor-provided patches.
Impact
The affected vulnerabilities impact organizations utilizing CODESYS industrial automation software. Successful exploitation could result in the unauthorized modification of process data or complete service unavailability, necessitating emergency maintenance in critical production environments.
Recommendation
Prioritize the identification of all instances of CODESYS Control Runtime and Gateway Client within the enterprise OT environment. Apply security updates provided by CODESYS immediately to mitigate the risks associated with CVE-2024-44336, CVE-2024-44337, CVE-2024-44338, CVE-2024-44339, CVE-2024-44340, CVE-2024-44341, CVE-2024-44342, CVE-2024-44343, and CVE-2024-44344. Ensure internal firewalls restrict access to industrial control interfaces to authorized engineering stations only.
Mitigations
Patch CODESYS Control Runtime and Gateway Client
CVE-2024-44336 through CVE-2024-44344