VendorsCODESYShmiall versions
Vulnerabilities

CODESYS Hmi

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

30CVEs
CVE-2020-10245
CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.
Published 2020-03-26 · Modified
10.0EPSS 0.025
CVE-2019-13548
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution.
Published 2019-09-13 · Modified
9.8EPSS 0.058
CVE-2019-18858
CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.
Published 2019-11-20 · Modified
9.8EPSS 0.019
CVE-2021-33485
CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
Published 2021-08-03 · Modified
9.8EPSS 0.011
CVE-2019-9008
An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over the runtime.
Published 2019-09-17 · Modified
8.8EPSS 0.019
CVE-2018-25048
Codesys Runtime Improper Limitation of a Pathname
Published 2023-03-23 · Modified
8.8EPSS 0.010
CVE-2019-13532
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.
Published 2019-09-13 · Modified
7.5EPSS 0.032
CVE-2020-15806
CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
Published 2020-07-22 · Modified
7.5EPSS 0.020
CVE-2019-9009
An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash.
Published 2019-09-17 · Modified
7.5EPSS 0.017
CVE-2021-29242
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.
Published 2021-05-03 · Modified
7.5EPSS 0.011
CVE-2021-36763
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.
Published 2021-08-03 · Modified
7.5EPSS 0.010
CVE-2022-30791
CODESYS V3: CmpBlkDrvTcp allows unauthenticated attackers to block all its available TCP connections
Published 2022-07-11 · Modified
7.5EPSS 0.009
CVE-2022-30792
CODESYS: CmpChannelServer, CmpChannelServerEmbedded allow unauthenticated attackers to block all their available communication channels
Published 2022-07-11 · Modified
7.5EPSS 0.009
CVE-2020-7052
CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.
Published 2020-01-24 · Modified
6.5EPSS 0.019
CVE-2020-12068
An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.
Published 2020-05-14 · Modified
6.5EPSS 0.009
CVE-2023-37559
CODESYS Improper Validation of Consistency within Input in multiple products
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37558
CODESYS Improper Validation of Consistency within Input in multiple products
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37557
CODESYS Heap-based Buffer Overflow in multiple products
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37556
CODESYS Improper Input Validation in CmpAppBP
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37555
CODESYS Improper Input Validation in CmpAppBP
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37554
CODESYS Improper Input Validation in CmpAppBP
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37553
CODESYS Improper Input Validation in CmpAppBP
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37552
CODESYS Improper Input Validation in CmpAppBP
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37550
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37549
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37548
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37547
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37546
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37545
CODESYS: Improper Input Validation in CmpApp component
Published 2023-08-03 · Modified
6.5EPSS 0.006
CVE-2023-37551
CODESYS Files or Directories Accessible to External Parties in CmpApp
Published 2023-08-03 · Modified
6.5EPSS 0.005