Attackers Chain Flaws to Backdoor CODESYS Applications and Deploy Malicious Code
ID: 7aa9fdb1-4341-50b6-b7aa-d107ea404152
STIX ID: report--7aa9fdb1-4341-50b6-b7aa-d107ea404152
Feed Name: Cyber Press
Threat Score
Nozomi Networks Labs disclosed three critical vulnerabilities in the CODESYS Control runtime that can be chained by a low-privileged authenticated attacker to extract credentials and cryptographic keys, modify PLC application backups (ZIP with weak CRC32), and restore backdoored applications that execute as root after reboot; CODESYS issued patches and mandatory code signing, and organizations are urged to patch, harden credentials, segment OT, and monitor for suspicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
