Vendor CVEs
Codesys
All CVEs
154 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-35227 | Hig | 0.53 | — | 0.00 | May 12, 2026 | An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections. | ||
| CVE-2022-32142 | Hig | 0.53 | 8.1 | 0.01 | Jun 24, 2022 | Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset, which can cause an out-of-bounds read or write access, resulting in denial-of-service condition or local memory overwrite, which… | ||
| CVE-2022-1965 | Hig | 0.53 | 8.1 | 0.01 | Jun 24, 2022 | Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required. | ||
| CVE-2022-22515 | Hig | 0.53 | 8.1 | 0.01 | Apr 7, 2022 | A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products. | ||
| CVE-2021-34595 | Hig | 0.53 | 8.1 | 0.01 | Oct 26, 2021 | A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite. | ||
| CVE-2026-44469 | Hig | 0.51 | 7.8 | 0.00 | May 26, 2026 | The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with… | ||
| CVE-2026-44468 | Hig | 0.51 | 7.8 | 0.00 | May 26, 2026 | The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the… | ||
| CVE-2025-41700 | Hig | 0.51 | 7.8 | 0.00 | Dec 1, 2025 | An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context. | ||
| CVE-2023-5751 | Hig | 0.51 | 7.8 | 0.00 | Jun 4, 2024 | A local attacker with low privileges can read and modify any users files and cause a DoS in the working directory of the affected products due to exposure of resource to wrong sphere. | ||
| CVE-2020-12069 | Hig | 0.51 | 7.8 | 0.00 | Dec 26, 2022 | In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the… | ||
| CVE-2022-22516 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2022 | The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space. | ||
| CVE-2021-21869 | Hig | 0.51 | 7.8 | 0.02 | Aug 25, 2021 | An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious… | ||
| CVE-2021-21868 | Hig | 0.51 | 7.8 | 0.02 | Aug 18, 2021 | An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious… | ||
| CVE-2021-21867 | Hig | 0.51 | 7.8 | 0.02 | Aug 18, 2021 | An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a… | ||
| CVE-2021-21863 | Hig | 0.51 | 7.8 | 0.01 | Aug 5, 2021 | A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to… | ||
| CVE-2021-21866 | Hig | 0.51 | 7.8 | 0.02 | Aug 2, 2021 | A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a… | ||
| CVE-2021-21865 | Hig | 0.51 | 7.8 | 0.01 | Aug 2, 2021 | A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Development System 3.5.16. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to… | ||
| CVE-2021-21864 | Hig | 0.51 | 7.8 | 0.02 | Aug 2, 2021 | A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a… | ||
| CVE-2021-29240 | Hig | 0.51 | 7.8 | 0.01 | May 4, 2021 | The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before installation and may be used to install CODESYS packages with malicious content. | ||
| CVE-2021-29239 | Hig | 0.51 | 7.8 | 0.00 | May 3, 2021 | CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries without first checking their validity. | ||
| CVE-2022-4048 | Hig | 0.50 | 7.7 | 0.00 | May 15, 2023 | Inadequate Encryption Strength in CODESYS Development System V3 versions prior to V3.5.18.40 allows an unauthenticated local attacker to access and manipulate code of the encrypted boot application. | ||
| CVE-2021-34586 | Hig | 0.50 | 7.5 | 0.13 | Oct 26, 2021 | In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the CODESYS web server and may result in a denial-of-service condition. | ||
| CVE-2026-3509 | Hig | 0.49 | 7.5 | 0.00 | Mar 24, 2026 | An unauthenticated remote attacker may be able to control the format string of messages processed by the Audit Log of the CODESYS Control runtime system, potentially resulting in a denial‑of‑service (DoS) condition. | ||
| CVE-2025-41738 | Hig | 0.49 | 7.5 | 0.00 | Dec 1, 2025 | An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition. | ||
| CVE-2025-41691 | Hig | 0.49 | 7.5 | 0.01 | Aug 4, 2025 | An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading to a denial-of-service (DoS) condition. | ||
| CVE-2025-1468 | Hig | 0.49 | 7.5 | 0.01 | Mar 18, 2025 | An unauthenticated remote attacker can gain access to sensitive information including authentication information when using CODESYS OPC UA Server with the non-default Basic128Rsa15 security policy. | ||
| CVE-2024-8175 | Hig | 0.49 | 7.5 | 0.01 | Sep 25, 2024 | An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS. | ||
| CVE-2024-5000 | Hig | 0.49 | 7.5 | 0.01 | Jun 4, 2024 | An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS products which can cause a DoS due to incorrect calculation of buffer size. | ||
| CVE-2022-47391 | Hig | 0.49 | 7.5 | 0.02 | May 15, 2023 | In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from invalid addresses leading to a denial of service. | ||
| CVE-2020-12067 | Hig | 0.49 | 7.5 | 0.01 | Dec 26, 2022 | In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password. | ||
| CVE-2022-30792 | Hig | 0.49 | 7.5 | 0.01 | Jul 11, 2022 | In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected. | ||
| CVE-2022-30791 | Hig | 0.49 | 7.5 | 0.01 | Jul 11, 2022 | In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected. | ||
| CVE-2022-31805 | Hig | 0.49 | 7.5 | 0.01 | Jun 24, 2022 | In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected. | ||
| CVE-2022-31804 | Hig | 0.49 | 7.5 | 0.01 | Jun 24, 2022 | The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated attacker may allocate an arbitrary amount of memory, which may lead to a crash of the Gateway due to an out-of-memory condition. | ||
| CVE-2022-22519 | Hig | 0.49 | 7.5 | 0.01 | Apr 7, 2022 | A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system. | ||
| CVE-2022-22517 | Hig | 0.49 | 7.5 | 0.01 | Apr 7, 2022 | An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed. | ||
| CVE-2022-22510 | Hig | 0.49 | 7.5 | 0.01 | Feb 2, 2022 | Codesys Profinet in version V4.2.0.0 is prone to null pointer dereference that allows a denial of service (DoS) attack of an unauthenticated user via SNMP. | ||
| CVE-2021-34593 | Hig | 0.49 | 7.5 | 0.03 | Oct 26, 2021 | In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be… | ||
| CVE-2021-34585 | Hig | 0.49 | 7.5 | 0.01 | Oct 26, 2021 | In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation. | ||
| CVE-2021-34583 | Hig | 0.49 | 7.5 | 0.08 | Oct 26, 2021 | Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22. | ||
| CVE-2021-36765 | Hig | 0.49 | 7.5 | 0.01 | Aug 4, 2021 | In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP stack that is executed by the CODESYS Control runtime system. | ||
| CVE-2021-36764 | Hig | 0.49 | 7.5 | 0.01 | Aug 4, 2021 | In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products and may result in a denial-of-service condition. | ||
| CVE-2021-36763 | Hig | 0.49 | 7.5 | 0.01 | Aug 3, 2021 | In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties. | ||
| CVE-2021-33486 | Hig | 0.49 | 7.5 | 0.01 | Aug 3, 2021 | All versions of the CODESYS V3 Runtime Toolkit for VxWorks from version V3.5.8.0 and before version V3.5.17.10 have Improper Handling of Exceptional Conditions. | ||
| CVE-2021-30195 | Hig | 0.49 | 7.5 | 0.07 | May 25, 2021 | CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation. | ||
| CVE-2021-30191 | Hig | 0.49 | 7.5 | 0.01 | May 25, 2021 | CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input. | ||
| CVE-2021-30186 | Hig | 0.49 | 7.5 | 0.07 | May 25, 2021 | CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow. | ||
| CVE-2021-29241 | Hig | 0.49 | 7.5 | 0.01 | May 3, 2021 | CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS). | ||
| CVE-2020-15806 | Hig | 0.49 | 7.5 | 0.02 | Jul 22, 2020 | CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation. | ||
| CVE-2019-5105 | Hig | 0.49 | 7.5 | 0.02 | Mar 26, 2020 | An exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S-Smart Software Solutions CODESYS GatewayService. A specially crafted packet can cause a large memcpy, resulting in an access violation and termination of the process. An attacker… |
- risk 0.53cvss —epss 0.00
An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections.
- risk 0.53cvss 8.1epss 0.01
Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset, which can cause an out-of-bounds read or write access, resulting in denial-of-service condition or local memory overwrite, which…
- risk 0.53cvss 8.1epss 0.01
Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required.
- risk 0.53cvss 8.1epss 0.01
A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.
- risk 0.53cvss 8.1epss 0.01
A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.
- risk 0.51cvss 7.8epss 0.00
The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with…
- risk 0.51cvss 7.8epss 0.00
The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the…
- risk 0.51cvss 7.8epss 0.00
An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.
- risk 0.51cvss 7.8epss 0.00
A local attacker with low privileges can read and modify any users files and cause a DoS in the working directory of the affected products due to exposure of resource to wrong sphere.
- risk 0.51cvss 7.8epss 0.00
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the…
- risk 0.51cvss 7.8epss 0.00
The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space.
- risk 0.51cvss 7.8epss 0.02
An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious…
- risk 0.51cvss 7.8epss 0.02
An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious…
- risk 0.51cvss 7.8epss 0.02
An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a…
- risk 0.51cvss 7.8epss 0.01
A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to…
- risk 0.51cvss 7.8epss 0.02
A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a…
- risk 0.51cvss 7.8epss 0.01
A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Development System 3.5.16. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to…
- risk 0.51cvss 7.8epss 0.02
A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a…
- risk 0.51cvss 7.8epss 0.01
The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before installation and may be used to install CODESYS packages with malicious content.
- risk 0.51cvss 7.8epss 0.00
CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries without first checking their validity.
- risk 0.50cvss 7.7epss 0.00
Inadequate Encryption Strength in CODESYS Development System V3 versions prior to V3.5.18.40 allows an unauthenticated local attacker to access and manipulate code of the encrypted boot application.
- risk 0.50cvss 7.5epss 0.13
In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the CODESYS web server and may result in a denial-of-service condition.
- risk 0.49cvss 7.5epss 0.00
An unauthenticated remote attacker may be able to control the format string of messages processed by the Audit Log of the CODESYS Control runtime system, potentially resulting in a denial‑of‑service (DoS) condition.
- risk 0.49cvss 7.5epss 0.00
An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.
- risk 0.49cvss 7.5epss 0.01
An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading to a denial-of-service (DoS) condition.
- risk 0.49cvss 7.5epss 0.01
An unauthenticated remote attacker can gain access to sensitive information including authentication information when using CODESYS OPC UA Server with the non-default Basic128Rsa15 security policy.
- risk 0.49cvss 7.5epss 0.01
An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS.
- risk 0.49cvss 7.5epss 0.01
An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS products which can cause a DoS due to incorrect calculation of buffer size.
- risk 0.49cvss 7.5epss 0.02
In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from invalid addresses leading to a denial of service.
- risk 0.49cvss 7.5epss 0.01
In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password.
- risk 0.49cvss 7.5epss 0.01
In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected.
- risk 0.49cvss 7.5epss 0.01
In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected.
- risk 0.49cvss 7.5epss 0.01
In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
- risk 0.49cvss 7.5epss 0.01
The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated attacker may allocate an arbitrary amount of memory, which may lead to a crash of the Gateway due to an out-of-memory condition.
- risk 0.49cvss 7.5epss 0.01
A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system.
- risk 0.49cvss 7.5epss 0.01
An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.
- risk 0.49cvss 7.5epss 0.01
Codesys Profinet in version V4.2.0.0 is prone to null pointer dereference that allows a denial of service (DoS) attack of an unauthenticated user via SNMP.
- risk 0.49cvss 7.5epss 0.03
In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be…
- risk 0.49cvss 7.5epss 0.01
In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation.
- risk 0.49cvss 7.5epss 0.08
Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.
- risk 0.49cvss 7.5epss 0.01
In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP stack that is executed by the CODESYS Control runtime system.
- risk 0.49cvss 7.5epss 0.01
In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products and may result in a denial-of-service condition.
- risk 0.49cvss 7.5epss 0.01
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.
- risk 0.49cvss 7.5epss 0.01
All versions of the CODESYS V3 Runtime Toolkit for VxWorks from version V3.5.8.0 and before version V3.5.17.10 have Improper Handling of Exceptional Conditions.
- risk 0.49cvss 7.5epss 0.07
CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.
- risk 0.49cvss 7.5epss 0.01
CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.
- risk 0.49cvss 7.5epss 0.07
CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.
- risk 0.49cvss 7.5epss 0.01
CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).
- risk 0.49cvss 7.5epss 0.02
CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
- risk 0.49cvss 7.5epss 0.02
An exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S-Smart Software Solutions CODESYS GatewayService. A specially crafted packet can cause a large memcpy, resulting in an access violation and termination of the process. An attacker…
Page 2 of 4