VYPR

Vendor CVEs

Codesys

All CVEs

154 total · sorted by risk
  • CVE-2012-6069CriJan 21, 2013
    risk 0.65cvss 10.0epss 0.03

    The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker to access files and directories outside the intended scope. This may allow an attacker to upload and download any file on the device. This could allow the …

  • CVE-2022-31806CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.01

    In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the controller.

  • CVE-2022-31802CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.01

    In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer…

  • CVE-2021-33485CriAug 3, 2021
    risk 0.64cvss 9.8epss 0.01

    CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.

  • CVE-2021-30193CriMay 25, 2021
    risk 0.64cvss 9.8epss 0.01

    CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.

  • CVE-2021-30192CriMay 25, 2021
    risk 0.64cvss 9.8epss 0.01

    CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.

  • CVE-2021-30190CriMay 25, 2021
    risk 0.64cvss 9.8epss 0.01

    CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.

  • CVE-2021-30189CriMay 25, 2021
    risk 0.64cvss 9.8epss 0.01

    CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.

  • CVE-2021-30188CriMay 25, 2021
    risk 0.64cvss 9.8epss 0.01

    CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.

  • CVE-2020-10245CriMar 26, 2020
    risk 0.64cvss 9.8epss 0.03

    CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.

  • CVE-2019-18858CriNov 20, 2019
    risk 0.64cvss 9.8epss 0.02

    CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.

  • CVE-2019-16265CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.02

    CODESYS V2.3 ENI server up to V3.2.2.24 has a Buffer Overflow.

  • CVE-2019-13548CriSep 13, 2019
    risk 0.64cvss 9.8epss 0.06

    CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution.

  • CVE-2019-9010CriAug 15, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of a communication channel. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are…

  • CVE-2018-10612CriJan 29, 2019
    risk 0.64cvss 9.8epss 0.01

    In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials.

  • CVE-2018-5440CriFeb 15, 2018
    risk 0.64cvss 9.8epss 0.03

    A Stack-based Buffer Overflow issue was discovered in 3S-Smart CODESYS Web Server. Specifically: all Microsoft Windows (also WinCE) based CODESYS web servers running stand-alone Version 2.3, or as part of the CODESYS runtime system running prior to Version V1.1.9.19. A crafted…

  • CVE-2017-6027CriMay 19, 2017
    risk 0.64cvss 9.8epss 0.03

    An Arbitrary File Upload issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2.3 and prior. A…

  • CVE-2017-6025CriMay 19, 2017
    risk 0.64cvss 9.8epss 0.02

    A Stack Buffer Overflow issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2.3 and prior. A malicious…

  • CVE-2012-6068CriJan 21, 2013
    risk 0.64cvss 9.8epss 0.05

    The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.

  • CVE-2021-34584CriOct 26, 2021
    risk 0.59cvss 9.1epss 0.01

    Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.

  • CVE-2021-30194CriMay 25, 2021
    risk 0.59cvss 9.1epss 0.01

    CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.

  • CVE-2026-35225HigApr 23, 2026
    risk 0.57cvss epss 0.00

    An unauthenticated remote attacker is able to exhaust all available TCP connections in the CODESYS EtherNet/IP adapter stack, preventing legitimate clients from establishing new connections.

  • CVE-2025-41660HigMar 24, 2026
    risk 0.57cvss 8.8epss 0.00

    A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.

  • CVE-2024-41969HigNov 18, 2024
    risk 0.57cvss 8.8epss 0.00

    A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication vulnerability which could lead to full system access and/or DoS.

  • CVE-2023-6357HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.01

    A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.

  • CVE-2022-4046HigAug 3, 2023
    risk 0.57cvss 8.8epss 0.01

    In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.

  • CVE-2023-3663HigAug 3, 2023
    risk 0.57cvss 8.8epss 0.01

    In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to manipulate the content of notifications received via HTTP by the CODESYS notification server.

  • CVE-2022-47390HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47389HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47388HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47387HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47386HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47385HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47384HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47383HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47382HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote…

  • CVE-2022-47381HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

  • CVE-2022-47380HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.01

    An authenticated remote attacker may use a stack based  out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

  • CVE-2022-47379HigMay 15, 2023
    risk 0.57cvss 8.8epss 0.02

    An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

  • CVE-2022-4224HigMar 23, 2023
    risk 0.57cvss 8.8epss 0.01

    In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.

  • CVE-2018-25048HigMar 23, 2023
    risk 0.57cvss 8.8epss 0.01

    The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to access and modify all system files as well as DoS the device.

  • CVE-2022-32143HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the PLC. All requests are processed on the controller only if no level 1 password is configured on the controller or if remote attacker…

  • CVE-2022-32138HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    In multiple CODESYS products, a remote attacker may craft a request which may cause an unexpected sign extension, resulting in a denial-of-service condition or memory overwrite.

  • CVE-2022-32137HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    In multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause a heap-based buffer overflow, resulting in a denial-of-service condition or memory overwrite. User interaction is not required.

  • CVE-2021-29238HigMay 3, 2021
    risk 0.57cvss 8.8epss 0.01

    CODESYS Automation Server before 1.16.0 allows cross-site request forgery (CSRF).

  • CVE-2020-6081HigMay 7, 2020
    risk 0.57cvss 8.8epss 0.02

    An exploitable code execution vulnerability exists in the PLC_Task functionality of 3S-Smart Software Solutions GmbH CODESYS Runtime 3.5.14.30. A specially crafted network request can cause remote code execution. An attacker can send a malicious packet to trigger this…

  • CVE-2019-9008HigSep 17, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over the runtime.

  • CVE-2019-9013HigAug 15, 2019
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the following CODESYS V3 products in all versions containing the…

  • CVE-2019-13538HigSep 17, 2019
    risk 0.56cvss 8.6epss 0.01

    3S-Smart Software Solutions GmbH CODESYS V3 Library Manager, all versions prior to 3.5.16.0, allows the system to display active library content without checking its validity, which may allow the contents of manipulated libraries to be displayed or executed. The issue also…

  • CVE-2025-41659HigAug 4, 2025
    risk 0.54cvss 8.3epss 0.00

    A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates as trusted. Although all services remain available, only…

Page 1 of 4