Using Extensions
Install and use only trusted extensions
Target group: End users, system administrators
Description: In CODESYS 4, extensions are not run in a security sandbox. They are only isolated from each other while being loaded. An installed extension has full permissions of the product and of the executing user, and is therefore part of the trusted base of the system – just like the product core itself.
Action: Install exclusively verified and approved extensions from trusted sources.
Reasoning: A malicious or compromised extension can perform any action the executing user is authorized to perform – including accessing any data and projects that the user is authorized to access.