Web Server
by Codesys
CVEs (13)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-30193 | Cri | 0.64 | 9.8 | 0.01 | May 25, 2021 | CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write. | ||
| CVE-2021-30192 | Cri | 0.64 | 9.8 | 0.01 | May 25, 2021 | CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check. | ||
| CVE-2021-30190 | Cri | 0.64 | 9.8 | 0.01 | May 25, 2021 | CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control. | ||
| CVE-2021-30189 | Cri | 0.64 | 9.8 | 0.01 | May 25, 2021 | CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow. | ||
| CVE-2019-13548 | Cri | 0.64 | 9.8 | 0.06 | Sep 13, 2019 | CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution. | ||
| CVE-2017-6027 | Cri | 0.64 | 9.8 | 0.03 | May 19, 2017 | An Arbitrary File Upload issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2.3 and prior. A… | ||
| CVE-2017-6025 | Cri | 0.64 | 9.8 | 0.02 | May 19, 2017 | A Stack Buffer Overflow issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2.3 and prior. A malicious… | ||
| CVE-2021-30194 | Cri | 0.59 | 9.1 | 0.01 | May 25, 2021 | CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read. | ||
| CVE-2022-31805 | Hig | 0.49 | 7.5 | 0.01 | Jun 24, 2022 | In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected. | ||
| CVE-2021-34585 | Hig | 0.49 | 7.5 | 0.01 | Oct 26, 2021 | In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation. | ||
| CVE-2021-34583 | Hig | 0.49 | 7.5 | 0.08 | Oct 26, 2021 | Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22. | ||
| CVE-2021-36763 | Hig | 0.49 | 7.5 | 0.01 | Aug 3, 2021 | In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties. | ||
| CVE-2021-30191 | Hig | 0.49 | 7.5 | 0.01 | May 25, 2021 | CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input. |
- risk 0.64cvss 9.8epss 0.01
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.
- risk 0.64cvss 9.8epss 0.01
CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.
- risk 0.64cvss 9.8epss 0.01
CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.
- risk 0.64cvss 9.8epss 0.01
CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.
- risk 0.64cvss 9.8epss 0.06
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution.
- risk 0.64cvss 9.8epss 0.03
An Arbitrary File Upload issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2.3 and prior. A…
- risk 0.64cvss 9.8epss 0.02
A Stack Buffer Overflow issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2.3 and prior. A malicious…
- risk 0.59cvss 9.1epss 0.01
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.
- risk 0.49cvss 7.5epss 0.01
In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
- risk 0.49cvss 7.5epss 0.01
In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation.
- risk 0.49cvss 7.5epss 0.08
Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.
- risk 0.49cvss 7.5epss 0.01
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.
- risk 0.49cvss 7.5epss 0.01
CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.