Hmi Sl
by Codesys
CVEs (28)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-20026 | Hig | 0.49 | 7.5 | 0.03 | Feb 19, 2019 | Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0. | ||
| CVE-2018-20025 | Hig | 0.49 | 7.5 | 0.03 | Feb 19, 2019 | Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0. | ||
| CVE-2022-22514 | Hig | 0.46 | 7.1 | 0.01 | Apr 7, 2022 | An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be… | ||
| CVE-2022-47393 | Med | 0.42 | 6.5 | 0.01 | May 15, 2023 | An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple versions of multiple CODESYS products to force a denial-of-service situation. | ||
| CVE-2022-47392 | Med | 0.42 | 6.5 | 0.01 | May 15, 2023 | An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which can lead to a denial-of-service condition. | ||
| CVE-2022-47378 | Med | 0.42 | 6.5 | 0.01 | May 15, 2023 | Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated remote attacker may craft specific requests that use the vulnerability leading to a denial-of-service condition. | ||
| CVE-2022-22513 | Med | 0.42 | 6.5 | 0.01 | Apr 7, 2022 | An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash. | ||
| CVE-2022-22508 | Med | 0.28 | 4.3 | 0.01 | May 15, 2023 | Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block consecutive logins of a specific type. |
- risk 0.49cvss 7.5epss 0.03
Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0.
- risk 0.49cvss 7.5epss 0.03
Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.
- risk 0.46cvss 7.1epss 0.01
An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be…
- risk 0.42cvss 6.5epss 0.01
An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple versions of multiple CODESYS products to force a denial-of-service situation.
- risk 0.42cvss 6.5epss 0.01
An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which can lead to a denial-of-service condition.
- risk 0.42cvss 6.5epss 0.01
Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated remote attacker may craft specific requests that use the vulnerability leading to a denial-of-service condition.
- risk 0.42cvss 6.5epss 0.01
An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.
- risk 0.28cvss 4.3epss 0.01
Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block consecutive logins of a specific type.
Page 2 of 2