V2 Runtime System Sp
by Codesys
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-30188 | Cri | 0.64 | 9.8 | 0.01 | May 25, 2021 | CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow. | ||
| CVE-2012-6068 | Cri | 0.64 | 9.8 | 0.05 | Jan 21, 2013 | The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service. | ||
| CVE-2018-25048 | Hig | 0.57 | 8.8 | 0.01 | Mar 23, 2023 | The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to access and modify all system files as well as DoS the device. | ||
| CVE-2021-30195 | Hig | 0.49 | 7.5 | 0.07 | May 25, 2021 | CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation. | ||
| CVE-2021-30186 | Hig | 0.49 | 7.5 | 0.07 | May 25, 2021 | CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow. | ||
| CVE-2021-30187 | Med | 0.34 | 5.3 | 0.00 | May 25, 2021 | CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command. |
- risk 0.64cvss 9.8epss 0.01
CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.
- risk 0.64cvss 9.8epss 0.05
The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.
- risk 0.57cvss 8.8epss 0.01
The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to access and modify all system files as well as DoS the device.
- risk 0.49cvss 7.5epss 0.07
CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.
- risk 0.49cvss 7.5epss 0.07
CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.
- risk 0.34cvss 5.3epss 0.00
CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.