Sceawere
Vulnerability Detail
CVE-2026-76992UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
CODESYS Gateway Client Memory Exhaustion
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 2h ago
- Vendor
- CODESYS
- Product
- Development System 3
- Attack Type
- CWE-770 Allocation of Resources Without Limits or Throttling
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-30T11:16:47.283Z",
"pubdate": "2026-09-30T11:16:47.283Z",
"executiveSummary": "The CODESYS Gateway Client is vulnerable to a memory exhaustion flaw triggered by insufficient validation of size fields within gateway responses. This vulnerability allows an unauthenticated remote attacker, who controls a malicious gateway server, to induce an out-of-memory condition.\nThe vulnerability type is classified as an improper input validation error leading to uncontrolled resource consumption. By sending a crafted response containing an excessively large size parameter, an attacker can force the client to allocate massive amounts of memory, effectively crashing the application.\nThe primary impact is a complete loss of availability, resulting in a Denial-of-Service (DoS) state. This affects the CODESYS Gateway Client and is particularly critical for industrial control environments where reliable communication with the gateway is essential for system operations.\nExploitation requires no authentication; however, the attacker must be able to act as or intercept the communication of a legitimate gateway to deliver the malicious payload to the client. The threat is primarily directed at the availability and stability of the system communication infrastructure.",
"technicalDetails": "The vulnerability resides in the memory management logic of the CODESYS Gateway Client, specifically within the component responsible for processing incoming gateway responses. When the client initiates communication with a gateway, it expects a data packet containing a size field that dictates the memory allocation necessary to buffer the incoming payload.\nThe root cause of this vulnerability is the absence of an upper bound check or a maximum buffer size validation when the client parses this size field. The client blindly trusts the value provided in the gateway response, invoking memory allocation functions to accommodate the requested size before verifying the physical feasibility or the sanity of the request.\nThe attack flow follows a predictable sequence: First, an attacker establishes a malicious gateway or compromises an existing one to intercept traffic directed at the client. When the client sends a request to the gateway, the attacker returns a response packet where the length field is set to an arbitrary, excessively high value. Upon receiving this response, the CODESYS Gateway Client attempts to allocate a memory buffer corresponding to this malicious length. Because the application lacks the logic to reject or cap the allocation based on available system resources or predefined protocol constraints, the memory manager is forced to commit large swaths of virtual memory.\nRepeated or sufficiently large requests trigger a catastrophic depletion of available memory, leading to an 'Out-of-Memory' (OOM) error. Depending on the operating system's memory management policies, this will cause the CODESYS Gateway Client process to terminate abruptly, hang, or destabilize the underlying host machine. This state results in a permanent loss of service until the application is restarted. The attack requires no privileges on the target machine and can be executed over the network, assuming the attacker has the ability to respond to the client's gateway discovery or connection requests. As the vulnerability is rooted in the protocol handling logic, it is inherently dangerous for any deployment exposed to potentially untrusted or compromised gateway environments."
}