Simulation Runtime
by Codesys
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-25048 | Hig | 0.57 | 8.8 | 0.01 | Mar 23, 2023 | The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to access and modify all system files as well as DoS the device. | ||
| CVE-2019-9008 | Hig | 0.57 | 8.8 | 0.02 | Sep 17, 2019 | An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over the runtime. | ||
| CVE-2020-15806 | Hig | 0.49 | 7.5 | 0.02 | Jul 22, 2020 | CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation. | ||
| CVE-2019-9009 | Hig | 0.49 | 7.5 | 0.02 | Sep 17, 2019 | An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash. | ||
| CVE-2021-29242 | Hig | 0.48 | 7.3 | 0.01 | May 3, 2021 | CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages. | ||
| CVE-2020-7052 | Med | 0.42 | 6.5 | 0.02 | Jan 24, 2020 | CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition. |
- risk 0.57cvss 8.8epss 0.01
The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to access and modify all system files as well as DoS the device.
- risk 0.57cvss 8.8epss 0.02
An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over the runtime.
- risk 0.49cvss 7.5epss 0.02
CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash.
- risk 0.48cvss 7.3epss 0.01
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.
- risk 0.42cvss 6.5epss 0.02
CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.