VendorsCODESYSdevelopment_systemall versions
Vulnerabilities

CODESYS Development System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

44CVEs
CVE-2019-9010
An issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of a communication channel. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control V3 Runtime System Toolkit, CODESYS Gateway V3, CODESYS V3 Development System.
Published 2019-08-15 · Modified
9.8EPSS 0.019
CVE-2021-21866
A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2021-08-02 · Modified
8.8EPSS 0.017
CVE-2021-21865
A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Development System 3.5.16. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2021-08-02 · Modified
8.8EPSS 0.013
CVE-2021-21863
A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2021-08-05 · Modified
8.8EPSS 0.012
CVE-2023-3663
CODESYS: Missing integrity check in CODESYS Development System
Published 2023-08-03 · Modified
8.8EPSS 0.010
CVE-2022-4224
CODESYS: Exposure of Resource to Wrong Sphere in CODESYS V3
Published 2023-03-23 · Modified
8.8EPSS 0.009
CVE-2019-9013
An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the following CODESYS V3 products in all versions containing the CmpUserMgr component are affected regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS V3 Simulation Runtime (part of the CODESYS Development System), CODESYS Control V3 Runtime System Toolkit, CODESYS HMI V3.
Published 2019-08-15 · Modified
8.8EPSS 0.003
CVE-2026-44468
Incorrect Default Permissions in CODESYS Development System
Published 2026-05-26 · Analyzed
8.5EPSS 0.001
CVE-2026-44469
Incorrect Default Permissions in CODESYS Development System
Published 2026-05-26 · Analyzed
8.5EPSS 0.001
CVE-2022-22515
A component of the CODESYS Control runtime system allows read and write access to configuration files
Published 2022-04-07 · Modified
8.1EPSS 0.011
CVE-2019-9012
An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication request may cause uncontrolled memory allocations in the affected CODESYS products and may result in a denial-of-service condition. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control V3 Runtime System Toolkit, CODESYS Gateway V3, CODESYS V3 Development System.
Published 2019-08-15 · Modified
7.8EPSS 0.018
CVE-2021-21864
A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2021-08-02 · Modified
7.8EPSS 0.017
CVE-2021-29240
The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before installation and may be used to install CODESYS packages with malicious content.
Published 2021-05-04 · Modified
7.8EPSS 0.009
CVE-2022-22516
CODESYS driver SysDrv3S allows SYSTEM users on Microsoft Windows to read and write in restricted memory space.
Published 2022-04-07 · Modified
7.8EPSS 0.003
CVE-2021-29239
CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries without first checking their validity.
Published 2021-05-03 · Modified
7.8EPSS 0.002
CVE-2018-20025
Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.
Published 2019-02-19 · Modified
7.5EPSS 0.026
CVE-2022-22519
Special HTTP(s) Requests can cause a buffer-read causing a crash of the webserver and the runtime system.
Published 2022-04-07 · Modified
7.5EPSS 0.015
CVE-2021-29241
CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).
Published 2021-05-03 · Modified
7.5EPSS 0.014
CVE-2022-22517
Communication Components in multiple CODESYS products vulnerable to communication channel disruption
Published 2022-04-07 · Modified
7.5EPSS 0.013
CVE-2022-31805
Insecure transmission of credentials
Published 2022-06-24 · Modified
7.5EPSS 0.010
CVE-2022-30791
CODESYS V3: CmpBlkDrvTcp allows unauthenticated attackers to block all its available TCP connections
Published 2022-07-11 · Modified
7.5EPSS 0.009
CVE-2022-30792
CODESYS: CmpChannelServer, CmpChannelServerEmbedded allow unauthenticated attackers to block all their available communication channels
Published 2022-07-11 · Modified
7.5EPSS 0.009
CVE-2021-34599
Improper Certificate Validation in CODESYS Git
Published 2021-12-01 · Modified
7.4EPSS 0.005
CVE-2023-3662
CODESYS: Vulnerability in CODESYS Development System allows for execution of binaries
Published 2023-08-03 · Modified
7.3EPSS 0.002
CVE-2023-3670
Codesys: Vulnerability in CODESYS Development System and CODESYS Scripting
Published 2023-07-28 · Modified
7.3EPSS 0.002
CVE-2022-22514
Untrusted Pointer Dereference in multiple CODESYS products can lead to a DoS.
Published 2022-04-07 · Modified
7.1EPSS 0.009
CVE-2022-22513
Null Pointer Dereference in multiple CODESYS products can lead to a DoS.
Published 2022-04-07 · Modified
6.5EPSS 0.010
CVE-2020-12068
An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.
Published 2020-05-14 · Modified
6.5EPSS 0.009
CVE-2023-37557
CODESYS Heap-based Buffer Overflow in multiple products
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37558
CODESYS Improper Validation of Consistency within Input in multiple products
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37559
CODESYS Improper Validation of Consistency within Input in multiple products
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37545
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37546
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37547
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37548
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37549
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37550
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37552
CODESYS Improper Input Validation in CmpAppBP
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37553
CODESYS Improper Input Validation in CmpAppBP
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37554
CODESYS Improper Input Validation in CmpAppBP
Published 2023-08-03 · Modified
6.5EPSS 0.006
1 / 2Next →