VYPR

Runtime Toolkit

by Codesys

CVEs (25)

  • CVE-2022-32136MedJun 24, 2022
    risk 0.42cvss 6.5epss 0.01

    In multiple CODESYS products, a low privileged remote attacker may craft a request that cause a read access to an uninitialized pointer, resulting in a denial-of-service. User interaction is not required.

  • CVE-2021-34596MedOct 26, 2021
    risk 0.42cvss 6.5epss 0.01

    A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition.

  • CVE-2019-19789MedDec 20, 2019
    risk 0.42cvss 6.5epss 0.01

    3S-Smart CODESYS SP Realtime NT before V2.3.7.28, CODESYS Runtime Toolkit 32 bit full before V2.4.7.54, and CODESYS PLCWinNT before V2.4.7.54 allow a NULL pointer dereference.

  • CVE-2025-41658MedAug 4, 2025
    risk 0.36cvss 5.5epss 0.00

    CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.

  • CVE-2021-30187MedMay 25, 2021
    risk 0.34cvss 5.3epss 0.00

    CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.

Page 2 of 2