CVE-2018-20025
Description
Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CODESYS V3 communication servers use insufficiently random values, enabling attack vectors that compromise data integrity and confidentiality.
Vulnerability
The vulnerability is a use of insufficiently random values in all CODESYS V3 products [1] versions prior to V3.5.14.0 [1][2]. The communication servers within these products generate random numbers that are not sufficiently random, which can be exploited in cryptographic or random number dependent contexts [1][2].
Exploitation
This vulnerability can be exploited remotely by an attacker with low skill level [2]. No authentication is required. The attacker can observe or manipulate communication to exploit the weakness in random number generation, potentially disguising the source of malicious communication packets [2].
Impact
Successful exploitation of this insufficient randomness weakness affects both the confidentiality and integrity of data stored on the device [2]. An attacker can disguise the source of malicious communication packets, potentially leading to man-in-the-middle attacks or other forms of data compromise [2].
Mitigation
The vendor released a patch in December 2018 [1]. Users are advised to update to CODESYS V3 version 3.5.14.0 or later [1][2]. As interim mitigations, CISA recommends using controllers and devices only in protected environments with firewalls and VPNs, and applying user management and access controls [2].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Kaspersky Lab/CODESYS V3 productsv5Range: prior V3.5.14.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/106251mitrevdb-entryx_refsource_BID
- ics-cert.kaspersky.com/advisories/klcert-advisories/2018/12/19/klcert-18-037-codesys-control-v3-use-of-insufficiently-random-values/mitrex_refsource_MISC
- ics-cert.us-cert.gov/advisories/ICSA-18-352-04mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.