Recently, Microsoft security experts revealed that the German industrial software giant Codesys (Codesys) system has 15 high-risk security vulnerabilities, which can lead to power plant shutdowns or the theft of critical system information. In September 2022, Microsoft intelligence threat expert Vladimir Tokarev reported to Codesys a security vulnerability in versions prior to Codesys Control V3 3.5.19.0. Codesys released a patch for the vulnerability in April 2023.
Codesys, the German industrial software giant headquartered in Germany, provides automation software for industrial control systems that are widely available in a large number of devices – about 1,000 different types of products produced by more than 500 manufacturers.

Security experts believe that these vulnerabilities are not easy to exploit, and attackers not only need to bypass authentication or steal login credentials, but also need to have deep knowledge of Codesys V3’s proprietary protocol and the architecture of the different services used by the protocol. But given the high risk of these vulnerabilities – which could shut down factories and cut power – experts strongly recommend that they be patched as soon as possible.
中文版