VYPR

Development System

by Codesys

CVEs (2)

  • CVE-2026-2364Mar 10, 2026
    risk 0.00cvss epss 0.00

    If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS Development System, a low privileged local attacker can gain elevated rights due to a TOCTOU vulnerability in the CODESYS installer.

  • CVE-2025-41700Dec 1, 2025
    risk 0.00cvss epss 0.00

    An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.