VYPR

Control For Raspberry Pi Sl

by Codesys

CVEs (53)

  • CVE-2019-9010CriAug 15, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of a communication channel. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are…

  • CVE-2018-10612CriJan 29, 2019
    risk 0.64cvss 9.8epss 0.01

    In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials.

  • CVE-2025-41660HigMar 24, 2026
    risk 0.57cvss 8.8epss 0.00

    A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.

  • CVE-2023-6357HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.01

    A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.

  • CVE-2022-4046HigAug 3, 2023
    risk 0.57cvss 8.8epss 0.01

    In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.

  • CVE-2022-47390HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47389HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47388HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47387HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47386HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47385HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47384HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47383HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47382HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47381HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

  • CVE-2022-47380HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated remote attacker may use a stack based  out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

  • CVE-2022-47379HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.02

    An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

  • CVE-2022-4224HigMar 23, 2023
    risk 0.57cvss 8.8epss 0.01

    In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.

  • CVE-2022-22515HigApr 7, 2022
    risk 0.53cvss 8.1epss 0.01

    A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.

  • CVE-2026-3509HigMar 24, 2026
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated remote attacker may be able to control the format string of messages processed by the Audit Log of the CODESYS Control runtime system, potentially resulting in a denial‑of‑service (DoS) condition.

Page 1 of 3