{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/codesys-gateway-client/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:dlink:dir-846w_firmware:fw100a43:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":5.3,"id":"CVE-2024-44336"},{"cvss":5.1,"id":"CVE-2024-44337"},{"cvss":8.8,"id":"CVE-2024-44340"},{"cvss":9.8,"id":"CVE-2024-44341"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CODESYS Control Runtime","CODESYS Gateway Client"],"_cs_severities":["medium"],"_cs_tags":["ics","industrial-control-system","vulnerability"],"_cs_type":"advisory","_cs_vendors":["CODESYS"],"content_html":"\u003cp\u003eThe BSI has released an advisory regarding multiple vulnerabilities identified in CODESYS Control Runtime and Gateway Client components. These flaws, tracked under CVE-2024-44336 through CVE-2024-44344, pose a significant risk to industrial environments where these components are deployed. Exploitation of these vulnerabilities may allow an unauthenticated or remote attacker to manipulate process data or induce a denial-of-service (DoS) condition, potentially leading to operational disruption of industrial control systems. As these components often operate in critical infrastructure, defenders must prioritize the assessment of their exposure and apply vendor-provided patches.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe affected vulnerabilities impact organizations utilizing CODESYS industrial automation software. Successful exploitation could result in the unauthorized modification of process data or complete service unavailability, necessitating emergency maintenance in critical production environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of all instances of CODESYS Control Runtime and Gateway Client within the enterprise OT environment. Apply security updates provided by CODESYS immediately to mitigate the risks associated with CVE-2024-44336, CVE-2024-44337, CVE-2024-44338, CVE-2024-44339, CVE-2024-44340, CVE-2024-44341, CVE-2024-44342, CVE-2024-44343, and CVE-2024-44344. Ensure internal firewalls restrict access to industrial control interfaces to authorized engineering stations only.\u003c/p\u003e\n","date_modified":"2026-10-02T14:20:49Z","date_published":"2026-10-02T14:20:49Z","id":"https://feed.craftedsignal.io/briefs/2026-10-codesys-vulnerabilities/","summary":"Multiple vulnerabilities in CODESYS Control Runtime and Gateway Client allow a remote attacker to manipulate data or cause a denial-of-service condition.","title":"Multiple Vulnerabilities in CODESYS Control Runtime and Gateway","url":"https://feed.craftedsignal.io/briefs/2026-10-codesys-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - CODESYS Gateway Client","version":"https://jsonfeed.org/version/1.1"}