CODESYS Control
by Codesys
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-4046 | Hig | 0.57 | 8.8 | 0.01 | Aug 3, 2023 | In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device. | ||
| CVE-2022-22516 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2022 | The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space. | ||
| CVE-2025-0694 | Med | 0.43 | 6.6 | 0.00 | Mar 18, 2025 | Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access. | ||
| CVE-2020-7052 | Med | 0.42 | 6.5 | 0.02 | Jan 24, 2020 | CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition. |
- risk 0.57cvss 8.8epss 0.01
In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.
- risk 0.51cvss 7.8epss 0.00
The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space.
- risk 0.43cvss 6.6epss 0.00
Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access.
- risk 0.42cvss 6.5epss 0.02
CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.