{
  "document": {
    "acknowledgments": [
      {
        "organization": "CERT@VDE",
        "summary": "coordination."
      }
    ],
    "aggregate_severity": {
      "namespace": "https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale",
      "text": "High"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-GB",
    "notes": [
      {
        "category": "summary",
        "text": "The Docker-based COMBIVIS Control Runtime service is affected by several vulnerabilities in CODESYS Runtime Toolkit 3.5.21.10. These vulnerabilities are resolved in COMBIVIS Control Runtime 2.1.0.",
        "title": "Summary"
      },
      {
        "category": "description",
        "text": "These vulnerabilities could expose PKI certificates and their private keys and allow them to be modified. They could also enable unauthenticated remote denial-of-service attacks against affected COMBIVIS Control Runtime systems.",
        "title": "Impact"
      },
      {
        "category": "description",
        "text": "Update the COMBIVIS Control Runtime service to version 2.1.0. This version uses CODESYS Runtime Toolkit 3.5.21.50 and resolves the vulnerabilities listed in this advisory.\n\nService updates can be installed directly on the device through the App Manager service in the web interface. Alternatively, updates can be installed through the NOA Cloud Portal at https://noa.keb-automation.com/.",
        "title": "Remediation"
      },
      {
        "category": "general",
        "text": "As part of a comprehensive security strategy, KEB Automation KG strongly recommends the following defence measures:\n\n* Use controllers and devices only in a protected environment to minimise network exposure and ensure that they are not accessible from outside.\n* Use firewalls to protect and separate the control system network from other networks.\n* Enable and use user management and password features.\n* Limit access to development and control systems using physical controls, operating system features, and other appropriate measures.\n* Use encrypted communication links.\n* Use virtual private network (VPN) tunnels if remote access is required.\n* Protect both development and control systems with up-to-date antivirus solutions.",
        "title": "General Recommendation"
      },
      {
        "category": "description",
        "text": "COMBIVIS Control Runtime is a NOA Service App that provides IEC 61131-3 runtime execution on KEB Automation devices based on the CODESYS Runtime Toolkit.",
        "title": "Product Description"
      },
      {
        "category": "legal_disclaimer",
        "text": "KEB Automation KG assumes no liability whatsoever for indirect, collateral, accidental or consequential losses\nthat occur by the distribution and/or use of this document or any losses in connection with the distribution and/or use of this document. All information published in this document is provided on good faith by KEB Automation KG.\nInsofar as permissible by law, however, none of this information shall establish any guarantee, commitment or\nliability on the part of KEB Automation KG.",
        "title": "Disclaimer"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "psirt@keb.de",
      "name": "KEB Automation KG",
      "namespace": "https://www.keb-automation.com/de/"
    },
    "references": [
      {
        "category": "external",
        "summary": "KEB PSIRT",
        "url": "https://www.keb-automation.com/de/unternehmen/qualitaetsstandards/psirt"
      },
      {
        "category": "external",
        "summary": "KEB Automation advisory overview at CERT@VDE",
        "url": "https://certvde.com/de/advisories/vendor/keb"
      },
      {
        "category": "self",
        "summary": "VDE-2026-105: KEB Automation: Multiple Vulnerabilities in COMBIVIS Control Runtime - HTML",
        "url": "https://certvde.com/en/advisories/VDE-2026-105"
      },
      {
        "category": "self",
        "summary": "VDE-2026-105: KEB Automation: Multiple Vulnerabilities in COMBIVIS Control Runtime - CSAF",
        "url": "https://keb-automation.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-105.json"
      }
    ],
    "title": "KEB Automation: Multiple Vulnerabilities in COMBIVIS Control Runtime",
    "tracking": {
      "aliases": [
        "VDE-2026-105"
      ],
      "current_release_date": "2026-10-08T10:00:00.000Z",
      "generator": {
        "date": "2026-10-07T10:49:58.272Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.6.12"
        }
      },
      "id": "VDE-2026-105",
      "initial_release_date": "2026-10-08T10:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-10-08T10:00:00.000Z",
          "number": "1.0.0",
          "summary": "Initial release"
        }
      ],
      "status": "final",
      "version": "1.0.0"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:generic/>=2.0.0-arm64|<2.1.0-arm64",
                    "product": {
                      "name": "COMBIVIS Control Runtime 2.0.0-arm64 <2.1.0-arm64",
                      "product_id": "CSAFPID-0001",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:keb_automation:combivis_control_runtime:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "2.1.0-arm64",
                    "product": {
                      "name": "COMBIVIS Control Runtime 2.1.0-arm64",
                      "product_id": "CSAFPID-0002",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:keb_automation:combivis_control_runtime:2.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "COMBIVIS Control Runtime"
              }
            ],
            "category": "product_family",
            "name": "Software"
          }
        ],
        "category": "vendor",
        "name": "KEB Automation"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-41659",
      "cwe": {
        "id": "CWE-732",
        "name": "Incorrect Permission Assignment for Critical Resource"
      },
      "notes": [
        {
          "category": "description",
          "text": "A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates as trusted. Although all services remain available, only unencrypted communication is possible if the certificates are deleted.",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-0002"
        ],
        "known_affected": [
          "CSAFPID-0001"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Update the COMBIVIS Control Runtime service to version 2.1.0.",
          "product_ids": [
            "CSAFPID-0001"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 8.3,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.3,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 8.3,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0001"
          ]
        }
      ],
      "title": "CODESYS Control PKI Exposure Enables Remote Certificate Access"
    },
    {
      "cve": "CVE-2025-41691",
      "cwe": {
        "id": "CWE-476",
        "name": "NULL Pointer Dereference"
      },
      "notes": [
        {
          "category": "description",
          "text": "An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading to a denial-of-service (DoS) condition.",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-0002"
        ],
        "known_affected": [
          "CSAFPID-0001"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Update the COMBIVIS Control Runtime service to version 2.1.0.",
          "product_ids": [
            "CSAFPID-0001"
          ],
          "restart_required": {
            "category": "system"
          }
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "environmentalScore": 7.5,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 7.5,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0001"
          ]
        }
      ],
      "title": "CODESYS Control DoS via Unauthenticated NULL Pointer Dereference"
    },
    {
      "cve": "CVE-2025-41739",
      "cwe": {
        "id": "CWE-125",
        "name": "Out-of-bounds Read"
      },
      "notes": [
        {
          "category": "description",
          "text": "An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-0002"
        ],
        "known_affected": [
          "CSAFPID-0001"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Update the COMBIVIS Control Runtime service to version 2.1.0.",
          "product_ids": [
            "CSAFPID-0001"
          ],
          "restart_required": {
            "category": "system"
          }
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 5.9,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 5.9,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0001"
          ]
        }
      ],
      "title": "CODESYS Control - Linux/QNX SysSocket flaw"
    },
    {
      "cve": "CVE-2025-41738",
      "cwe": {
        "id": "CWE-843",
        "name": "Access of Resource Using Incompatible Type ('Type Confusion')"
      },
      "notes": [
        {
          "category": "description",
          "text": "An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-0002"
        ],
        "known_affected": [
          "CSAFPID-0001"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Update the COMBIVIS Control Runtime service to version 2.1.0.",
          "product_ids": [
            "CSAFPID-0001"
          ],
          "restart_required": {
            "category": "system"
          }
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "environmentalScore": 7.5,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 7.5,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0001"
          ]
        }
      ],
      "title": "CODESYS Control - Invalid type usage in visualization"
    }
  ]
}