Codesys is a comprehensive software platform used for programming and configuring industrial automation and control systems, such as programmable logic controllers (PLCs) and embedded controllers. It is widely adopted across manufacturing, energy, and infrastructure sectors by engineers and system integrators to streamline development and operation of industrial processes. Its flexibility supports multiple hardware vendors, making it a cornerstone of modern operational technology environments.
The vulnerability arises when Codesys services are inadvertently exposed to the internet without proper security controls. This often occurs due to misconfigured network settings, default configurations, or lack of awareness about the risks of direct internet connectivity. Attackers can exploit this exposure to gain unauthorized access to critical industrial systems, potentially disrupting operations or causing physical damage.
Technically, the scanner targets the Codesys runtime service, typically listening on TCP port 11740 or other custom ports. It sends a probe to detect the presence of the service banner or response, identifying assets that are reachable from the internet. This detection is critical for assessing the attack surface of industrial control networks and prioritizing remediation efforts.
If exploited, an attacker could gain full control over the affected PLC or controller, allowing them to modify logic, disrupt processes, or cause equipment damage. This could lead to production downtime, safety hazards, and significant financial losses. In critical infrastructure, such as power grids or water treatment plants, the impact could be catastrophic, affecting public safety and national security.
- Restrict internet access to Codesys services using firewalls or access control lists to allow only trusted IP addresses.
- Ensure all default credentials are replaced with strong, unique passwords for every Codesys device.
- Regularly update and patch Codesys software to the latest version to fix known vulnerabilities.
- Monitor network traffic for unauthorized access attempts to Codesys services using intrusion detection systems.
- Conduct regular security assessments and penetration testing on industrial control systems to identify exposures.
- Implement network segmentation to isolate industrial control systems from corporate and public networks.
- Disable unnecessary Codesys services and features on devices that do not require remote access.
- Use VPNs or other encrypted tunnels for any required remote access to Codesys environments.
Get AI-powered remediation steps tailored to your asset.
Try AI Solutions →