VYPR

Control V3 Runtime System Toolkit

by Codesys

CVEs (59)

  • CVE-2023-37554MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37553MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37552MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37551MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communication requests can utilize the CmpApp component to download files with any file extensions to the controller. In contrast to the regular file download…

  • CVE-2023-37550MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37549MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37548MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37547MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37546MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37545MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…

  • CVE-2022-47393MedMay 15, 2023
    risk 0.42cvss 6.5epss 0.01

    An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple versions of multiple CODESYS products to force a denial-of-service situation.

  • CVE-2022-47392MedMay 15, 2023
    risk 0.42cvss 6.5epss 0.01

    An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which can lead to a denial-of-service condition.

  • CVE-2022-47378MedMay 15, 2023
    risk 0.42cvss 6.5epss 0.01

    Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated remote attacker may craft specific requests that use the vulnerability leading to a denial-of-service condition.

  • CVE-2022-22518MedApr 7, 2022
    risk 0.42cvss 6.5epss 0.01

    A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymous access to components part of the applied security policy.

  • CVE-2022-22513MedApr 7, 2022
    risk 0.42cvss 6.5epss 0.01

    An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.

  • CVE-2020-12068MedMay 14, 2020
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.

  • CVE-2020-7052MedJan 24, 2020
    risk 0.42cvss 6.5epss 0.02

    CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.

  • CVE-2025-41739MedDec 1, 2025
    risk 0.38cvss 5.9epss 0.00

    An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.

  • CVE-2022-22508MedMay 15, 2023
    risk 0.28cvss 4.3epss 0.01

    Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block consecutive logins of a specific type.

Page 3 of 3