VYPR

Web Server

by Codesys

CVEs (13)

  • CVE-2021-30193CriMay 25, 2021
    risk 0.64cvss 9.8epss 0.01

    CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.

  • CVE-2021-30192CriMay 25, 2021
    risk 0.64cvss 9.8epss 0.01

    CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.

  • CVE-2021-30190CriMay 25, 2021
    risk 0.64cvss 9.8epss 0.01

    CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.

  • CVE-2021-30189CriMay 25, 2021
    risk 0.64cvss 9.8epss 0.01

    CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.

  • CVE-2019-13548CriSep 13, 2019
    risk 0.64cvss 9.8epss 0.06

    CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution.

  • CVE-2017-6027CriMay 19, 2017
    risk 0.64cvss 9.8epss 0.03

    An Arbitrary File Upload issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2.3 and prior. A…

  • CVE-2017-6025CriMay 19, 2017
    risk 0.64cvss 9.8epss 0.02

    A Stack Buffer Overflow issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2.3 and prior. A malicious…

  • CVE-2021-30194CriMay 25, 2021
    risk 0.59cvss 9.1epss 0.01

    CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.

  • CVE-2022-31805HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.

  • CVE-2021-34585HigOct 26, 2021
    risk 0.49cvss 7.5epss 0.01

    In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation.

  • CVE-2021-34583HigOct 26, 2021
    risk 0.49cvss 7.5epss 0.08

    Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.

  • CVE-2021-36763HigAug 3, 2021
    risk 0.49cvss 7.5epss 0.01

    In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.

  • CVE-2021-30191HigMay 25, 2021
    risk 0.49cvss 7.5epss 0.01

    CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.