VendorsCODESYShmi_slany version
Vulnerabilities

CODESYS Hmi Sl any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2018-10612
In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials.
Published 2019-01-29 · Modified
10.0EPSS 0.013
CVE-2022-4224
CODESYS: Exposure of Resource to Wrong Sphere in CODESYS V3
Published 2023-03-23 · Modified
8.8EPSS 0.009
CVE-2022-4046
CODESYS: Improper memory restrictions fro CODESYS Control
Published 2023-08-03 · Modified
8.8EPSS 0.009
CVE-2019-9013
An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the following CODESYS V3 products in all versions containing the CmpUserMgr component are affected regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS V3 Simulation Runtime (part of the CODESYS Development System), CODESYS Control V3 Runtime System Toolkit, CODESYS HMI V3.
Published 2019-08-15 · Modified
8.8EPSS 0.003
CVE-2022-22515
A component of the CODESYS Control runtime system allows read and write access to configuration files
Published 2022-04-07 · Modified
8.1EPSS 0.011
CVE-2018-20026
Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0.
Published 2019-02-19 · Modified
7.5EPSS 0.030
CVE-2018-20025
Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.
Published 2019-02-19 · Modified
7.5EPSS 0.026
CVE-2022-22519
Special HTTP(s) Requests can cause a buffer-read causing a crash of the webserver and the runtime system.
Published 2022-04-07 · Modified
7.5EPSS 0.015
CVE-2022-22517
Communication Components in multiple CODESYS products vulnerable to communication channel disruption
Published 2022-04-07 · Modified
7.5EPSS 0.013
CVE-2022-31805
Insecure transmission of credentials
Published 2022-06-24 · Modified
7.5EPSS 0.010
CVE-2025-41738
CODESYS Control - Invalid type usage in visualization
Published 2025-12-01 · Analyzed
7.5EPSS 0.004
CVE-2022-22514
Untrusted Pointer Dereference in multiple CODESYS products can lead to a DoS.
Published 2022-04-07 · Modified
7.1EPSS 0.009
CVE-2022-22513
Null Pointer Dereference in multiple CODESYS products can lead to a DoS.
Published 2022-04-07 · Modified
6.5EPSS 0.010