VendorsCODESYScontrol_runtime_system_toolkitall versions
Vulnerabilities

CODESYS Control Runtime System Toolkit

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

52CVEs
CVE-2020-10245
CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.
Published 2020-03-26 · Modified
10.0EPSS 0.025
CVE-2019-13548
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution.
Published 2019-09-13 · Modified
9.8EPSS 0.058
CVE-2019-18858
CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.
Published 2019-11-20 · Modified
9.8EPSS 0.019
CVE-2021-33485
CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
Published 2021-08-03 · Modified
9.8EPSS 0.011
CVE-2022-47379
CODESYS: Multiple products prone to out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.020
CVE-2022-47386
CODESYS: Multiple products prone to stack based out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.014
CVE-2022-47385
CODESYS: Multiple products prone to stack based out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.014
CVE-2022-47383
CODESYS: Multiple products prone to stack based out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.013
CVE-2022-47388
CODESYS: Multiple products prone to stack based out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.013
CVE-2022-47381
CODESYS: Multiple products prone to stack based out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.013
CVE-2022-47380
CODESYS: Multiple products prone to out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.013
CVE-2022-47382
CODESYS: Multiple products prone to stack based out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.013
CVE-2022-47384
CODESYS: Multiple products prone to stack based out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.013
CVE-2022-47387
CODESYS: Multiple products prone to stack based out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.013
CVE-2022-47390
CODESYS: Multiple products prone to stack based out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.013
CVE-2022-47389
CODESYS: Multiple products prone to stack based out-of-bounds write
Published 2023-05-15 · Analyzed
8.8EPSS 0.013
CVE-2022-4046
CODESYS: Improper memory restrictions fro CODESYS Control
Published 2023-08-03 · Modified
8.8EPSS 0.009
CVE-2022-22515
A component of the CODESYS Control runtime system allows read and write access to configuration files
Published 2022-04-07 · Modified
8.1EPSS 0.011
CVE-2019-13532
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.
Published 2019-09-13 · Modified
7.5EPSS 0.032
CVE-2020-15806
CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
Published 2020-07-22 · Modified
7.5EPSS 0.020
CVE-2022-47391
CODESYS: Multiple products prone to Improper Input Validation
Published 2023-05-15 · Analyzed
7.5EPSS 0.019
CVE-2022-22519
Special HTTP(s) Requests can cause a buffer-read causing a crash of the webserver and the runtime system.
Published 2022-04-07 · Modified
7.5EPSS 0.015
CVE-2021-29241
CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).
Published 2021-05-03 · Modified
7.5EPSS 0.014
CVE-2022-22517
Communication Components in multiple CODESYS products vulnerable to communication channel disruption
Published 2022-04-07 · Modified
7.5EPSS 0.013
CVE-2021-29242
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.
Published 2021-05-03 · Modified
7.5EPSS 0.011
CVE-2021-36763
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.
Published 2021-08-03 · Modified
7.5EPSS 0.010
CVE-2022-30791
CODESYS V3: CmpBlkDrvTcp allows unauthenticated attackers to block all its available TCP connections
Published 2022-07-11 · Modified
7.5EPSS 0.009
CVE-2022-30792
CODESYS: CmpChannelServer, CmpChannelServerEmbedded allow unauthenticated attackers to block all their available communication channels
Published 2022-07-11 · Modified
7.5EPSS 0.009
CVE-2022-22514
Untrusted Pointer Dereference in multiple CODESYS products can lead to a DoS.
Published 2022-04-07 · Modified
7.1EPSS 0.009
CVE-2020-7052
CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.
Published 2020-01-24 · Modified
6.5EPSS 0.019
CVE-2022-22513
Null Pointer Dereference in multiple CODESYS products can lead to a DoS.
Published 2022-04-07 · Modified
6.5EPSS 0.010
CVE-2022-47393
CODESYS: Multiple products prone to improperly restricted memory operations
Published 2023-05-15 · Analyzed
6.5EPSS 0.010
CVE-2020-12068
An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.
Published 2020-05-14 · Modified
6.5EPSS 0.009
CVE-2022-47378
CODESYS: Multiple products prone to Improper Input Validation
Published 2023-05-15 · Analyzed
6.5EPSS 0.009
CVE-2022-47392
CODESYS: Multiple products prone to Improper Input Validation
Published 2023-05-15 · Analyzed
6.5EPSS 0.009
CVE-2023-37545
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37546
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37549
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37548
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37547
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
1 / 2Next →