VendorsCODESYScontrol_win_slall versions
Vulnerabilities

CODESYS Control Win SL

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

30CVEs
CVE-2018-10612
In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials.
Published 2019-01-29 · Modified
10.0EPSS 0.013
CVE-2021-33485
CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
Published 2021-08-03 · Modified
9.8EPSS 0.011
CVE-2022-4224
CODESYS: Exposure of Resource to Wrong Sphere in CODESYS V3
Published 2023-03-23 · Modified
8.8EPSS 0.009
CVE-2022-4046
CODESYS: Improper memory restrictions fro CODESYS Control
Published 2023-08-03 · Modified
8.8EPSS 0.009
CVE-2019-9013
An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the following CODESYS V3 products in all versions containing the CmpUserMgr component are affected regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS V3 Simulation Runtime (part of the CODESYS Development System), CODESYS Control V3 Runtime System Toolkit, CODESYS HMI V3.
Published 2019-08-15 · Modified
8.8EPSS 0.003
CVE-2022-22515
A component of the CODESYS Control runtime system allows read and write access to configuration files
Published 2022-04-07 · Modified
8.1EPSS 0.011
CVE-2022-22516
CODESYS driver SysDrv3S allows SYSTEM users on Microsoft Windows to read and write in restricted memory space.
Published 2022-04-07 · Modified
7.8EPSS 0.003
CVE-2018-20026
Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0.
Published 2019-02-19 · Modified
7.5EPSS 0.030
CVE-2018-20025
Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.
Published 2019-02-19 · Modified
7.5EPSS 0.026
CVE-2022-22519
Special HTTP(s) Requests can cause a buffer-read causing a crash of the webserver and the runtime system.
Published 2022-04-07 · Modified
7.5EPSS 0.015
CVE-2022-22517
Communication Components in multiple CODESYS products vulnerable to communication channel disruption
Published 2022-04-07 · Modified
7.5EPSS 0.013
CVE-2021-36763
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.
Published 2021-08-03 · Modified
7.5EPSS 0.010
CVE-2025-41738
CODESYS Control - Invalid type usage in visualization
Published 2025-12-01 · Analyzed
7.5EPSS 0.004
CVE-2022-22514
Untrusted Pointer Dereference in multiple CODESYS products can lead to a DoS.
Published 2022-04-07 · Modified
7.1EPSS 0.009
CVE-2022-22513
Null Pointer Dereference in multiple CODESYS products can lead to a DoS.
Published 2022-04-07 · Modified
6.5EPSS 0.010
CVE-2023-37552
CODESYS Improper Input Validation in CmpAppBP
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37559
CODESYS Improper Validation of Consistency within Input in multiple products
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37558
CODESYS Improper Validation of Consistency within Input in multiple products
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37557
CODESYS Heap-based Buffer Overflow in multiple products
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37556
CODESYS Improper Input Validation in CmpAppBP
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37555
CODESYS Improper Input Validation in CmpAppBP
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37554
CODESYS Improper Input Validation in CmpAppBP
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37553
CODESYS Improper Input Validation in CmpAppBP
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37550
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37549
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37548
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37547
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37546
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37545
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37551
CODESYS Files or Directories Accessible to External Parties in CmpApp
Published 2023-08-03 · Modified
6.5EPSS 0.005