VendorsCODESYScontrol_for_plcnextany version
Vulnerabilities

CODESYS Control for PLCnext any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2020-10245
CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.
Published 2020-03-26 · Modified
10.0EPSS 0.025
CVE-2019-18858
CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.
Published 2019-11-20 · Modified
9.8EPSS 0.019
CVE-2020-12069
CODESYS V3 prone to Inadequate Password Hashing
Published 2022-12-26 · Analyzed
7.8EPSS 0.002
CVE-2020-15806
CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
Published 2020-07-22 · Modified
7.5EPSS 0.020
CVE-2022-30791
CODESYS V3: CmpBlkDrvTcp allows unauthenticated attackers to block all its available TCP connections
Published 2022-07-11 · Modified
7.5EPSS 0.009
CVE-2022-30792
CODESYS: CmpChannelServer, CmpChannelServerEmbedded allow unauthenticated attackers to block all their available communication channels
Published 2022-07-11 · Modified
7.5EPSS 0.009
CVE-2020-7052
CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.
Published 2020-01-24 · Modified
6.5EPSS 0.019
CVE-2020-12068
An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.
Published 2020-05-14 · Modified
6.5EPSS 0.009