VYPR

Control For Wago Touch Panels 600 Sl

by Codesys

CVEs (43)

  • CVE-2023-6357HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.01

    A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.

  • CVE-2022-4046HigAug 3, 2023
    risk 0.57cvss 8.8epss 0.01

    In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.

  • CVE-2022-47390HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47389HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47388HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47387HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47386HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47385HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47384HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47383HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47382HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47381HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

  • CVE-2022-47380HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated remote attacker may use a stack based  out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

  • CVE-2022-47379HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.02

    An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

  • CVE-2022-4224HigMar 23, 2023
    risk 0.57cvss 8.8epss 0.01

    In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.

  • CVE-2022-22515HigApr 7, 2022
    risk 0.53cvss 8.1epss 0.01

    A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.

  • CVE-2025-41738HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.

  • CVE-2022-47391HigMay 15, 2023
    risk 0.49cvss 7.5epss 0.02

    In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from invalid addresses leading to a denial of service.

  • CVE-2022-22519HigApr 7, 2022
    risk 0.49cvss 7.5epss 0.01

    A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system.

  • CVE-2022-22517HigApr 7, 2022
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.

Page 1 of 3