VendorsCODESYScontrol_for_iot2000_slany version
Vulnerabilities

CODESYS Control for IOT2000 SL any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

52CVEs
CVE-2018-10612
In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials.
Published 2019-01-29 · Modified
10.0EPSS 0.013
CVE-2019-9010
An issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of a communication channel. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control V3 Runtime System Toolkit, CODESYS Gateway V3, CODESYS V3 Development System.
Published 2019-08-15 · Modified
9.8EPSS 0.019
CVE-2022-47379
CODESYS: Multiple products prone to out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.020
CVE-2022-47386
CODESYS: Multiple products prone to stack based out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.014
CVE-2022-47385
CODESYS: Multiple products prone to stack based out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.014
CVE-2022-47388
CODESYS: Multiple products prone to stack based out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.013
CVE-2022-47381
CODESYS: Multiple products prone to stack based out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.013
CVE-2022-47380
CODESYS: Multiple products prone to out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.013
CVE-2022-47383
CODESYS: Multiple products prone to stack based out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.013
CVE-2022-47384
CODESYS: Multiple products prone to stack based out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.013
CVE-2022-47382
CODESYS: Multiple products prone to stack based out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.013
CVE-2022-47387
CODESYS: Multiple products prone to stack based out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.013
CVE-2022-47390
CODESYS: Multiple products prone to stack based out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.013
CVE-2022-47389
CODESYS: Multiple products prone to stack based out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.013
CVE-2023-6357
OS Command Injection in multiple CODESYS products
Published 2023-12-05 · Modified
8.8EPSS 0.010
CVE-2022-4224
CODESYS: Exposure of Resource to Wrong Sphere in CODESYS V3
Published 2023-03-23 · Modified
8.8EPSS 0.009
CVE-2022-4046
CODESYS: Improper memory restrictions fro CODESYS Control
Published 2023-08-03 · Modified
8.8EPSS 0.009
CVE-2019-9013
An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the following CODESYS V3 products in all versions containing the CmpUserMgr component are affected regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS V3 Simulation Runtime (part of the CODESYS Development System), CODESYS Control V3 Runtime System Toolkit, CODESYS HMI V3.
Published 2019-08-15 · Modified
8.8EPSS 0.003
CVE-2022-22515
A component of the CODESYS Control runtime system allows read and write access to configuration files
Published 2022-04-07 · Modified
8.1EPSS 0.011
CVE-2019-9012
An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication request may cause uncontrolled memory allocations in the affected CODESYS products and may result in a denial-of-service condition. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control V3 Runtime System Toolkit, CODESYS Gateway V3, CODESYS V3 Development System.
Published 2019-08-15 · Modified
7.8EPSS 0.018
CVE-2018-20026
Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0.
Published 2019-02-19 · Modified
7.5EPSS 0.030
CVE-2018-20025
Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.
Published 2019-02-19 · Modified
7.5EPSS 0.026
CVE-2022-47391
CODESYS: Multiple products prone to Improper Input Validation
Published 2023-05-15 · Analyzed
7.5EPSS 0.019
CVE-2022-22519
Special HTTP(s) Requests can cause a buffer-read causing a crash of the webserver and the runtime system.
Published 2022-04-07 · Modified
7.5EPSS 0.015
CVE-2021-29241
CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).
Published 2021-05-03 · Modified
7.5EPSS 0.014
CVE-2022-22517
Communication Components in multiple CODESYS products vulnerable to communication channel disruption
Published 2022-04-07 · Modified
7.5EPSS 0.013
CVE-2021-29242
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.
Published 2021-05-03 · Modified
7.5EPSS 0.011
CVE-2022-30791
CODESYS V3: CmpBlkDrvTcp allows unauthenticated attackers to block all its available TCP connections
Published 2022-07-11 · Modified
7.5EPSS 0.009
CVE-2022-30792
CODESYS: CmpChannelServer, CmpChannelServerEmbedded allow unauthenticated attackers to block all their available communication channels
Published 2022-07-11 · Modified
7.5EPSS 0.009
CVE-2025-41738
CODESYS Control - Invalid type usage in visualization
Published 2025-12-01 · Analyzed
7.5EPSS 0.004
CVE-2022-22514
Untrusted Pointer Dereference in multiple CODESYS products can lead to a DoS.
Published 2022-04-07 · Modified
7.1EPSS 0.009
CVE-2022-22513
Null Pointer Dereference in multiple CODESYS products can lead to a DoS.
Published 2022-04-07 · Modified
6.5EPSS 0.010
CVE-2022-47393
CODESYS: Multiple products prone to improperly restricted memory operations
Published 2023-05-15 · Analyzed
6.5EPSS 0.010
CVE-2022-47378
CODESYS: Multiple products prone to Improper Input Validation
Published 2023-05-15 · Analyzed
6.5EPSS 0.009
CVE-2022-47392
CODESYS: Multiple products prone to Improper Input Validation
Published 2023-05-15 · Analyzed
6.5EPSS 0.009
CVE-2023-37545
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37546
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37547
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37548
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37552
CODESYS Improper Input Validation in CmpAppBP
Published 2023-08-03 · Modified
6.5EPSS 0.006
1 / 2Next →