VYPR

Control For Wago Touch Panels 600 Sl

by Codesys

CVEs (43)

  • CVE-2021-29242HigMay 3, 2021
    risk 0.48cvss 7.3epss 0.01

    CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.

  • CVE-2022-22514HigApr 7, 2022
    risk 0.46cvss 7.1epss 0.01

    An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be…

  • CVE-2023-37559MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37558MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37557MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.

  • CVE-2023-37556MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37555MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37554MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37553MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37552MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37551MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communication requests can utilize the CmpApp component to download files with any file extensions to the controller. In contrast to the regular file download…

  • CVE-2023-37550MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37549MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37548MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37547MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37546MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37545MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…

  • CVE-2022-47393MedMay 15, 2023
    risk 0.42cvss 6.5epss 0.01

    An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple versions of multiple CODESYS products to force a denial-of-service situation.

  • CVE-2022-47392MedMay 15, 2023
    risk 0.42cvss 6.5epss 0.01

    An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which can lead to a denial-of-service condition.

  • CVE-2022-47378MedMay 15, 2023
    risk 0.42cvss 6.5epss 0.01

    Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated remote attacker may craft specific requests that use the vulnerability leading to a denial-of-service condition.