VendorsCODESYSplcwinntall versions
Vulnerabilities

CODESYS PLCWinNT

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2022-31806
Insecure default settings in CODESYS Runtime Toolkit 32 bit full and CODESYS PLCWinNT
Published 2022-06-24 · Modified
9.8EPSS 0.012
CVE-2022-32137
CODESYS Runtime System prone to heap based buffer overflow
Published 2022-06-24 · Modified
8.8EPSS 0.014
CVE-2022-32143
CODESYS runtime system prone to directory acces
Published 2022-06-24 · Modified
8.8EPSS 0.012
CVE-2022-32138
CODESYS runtime system prone to denial of service due to Unexpected Sign Extension
Published 2022-06-24 · Modified
8.8EPSS 0.012
CVE-2022-1965
CODESYS runtime system prone to file deletion due to improper error handling
Published 2022-06-24 · Modified
8.1EPSS 0.011
CVE-2022-32142
CODESYS runtime system prone to denial of service due to use of out of range pointer
Published 2022-06-24 · Modified
8.1EPSS 0.011
CVE-2021-34595
CODESYS V2 runtime: out-of-bounds read or write access may result in denial-of-service
Published 2021-10-26 · Analyzed
8.1EPSS 0.009
CVE-2021-30186
CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.
Published 2021-05-25 · Analyzed
7.5EPSS 0.074
CVE-2021-30195
CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.
Published 2021-05-25 · Analyzed
7.5EPSS 0.072
CVE-2021-34593
CODESYS V2 runtime: unauthenticated invalid requests may result in denial-of-service
Published 2021-10-26 · Analyzed
7.5EPSS 0.027
CVE-2022-31805
Insecure transmission of credentials
Published 2022-06-24 · Modified
7.5EPSS 0.010
CVE-2019-19789
3S-Smart CODESYS SP Realtime NT before V2.3.7.28, CODESYS Runtime Toolkit 32 bit full before V2.4.7.54, and CODESYS PLCWinNT before V2.4.7.54 allow a NULL pointer dereference.
Published 2019-12-20 · Modified
6.5EPSS 0.012
CVE-2022-32140
CODESYS runtime system prone to denial of service due to buffer copy
Published 2022-06-24 · Modified
6.5EPSS 0.010
CVE-2022-32136
Codesys runtime systems: Access of uninitialised pointer lead to denial of service.
Published 2022-06-24 · Modified
6.5EPSS 0.010
CVE-2022-32139
CODESYS runtime system prone to denial of service due to out of bounds read
Published 2022-06-24 · Modified
6.5EPSS 0.010
CVE-2022-32141
CODESYS runtime system prone to denial of service due to buffer over read
Published 2022-06-24 · Modified
6.5EPSS 0.010
CVE-2021-34596
CODESYS V2 runtime: Access of Uninitialized Pointer may result in denial-of-service
Published 2021-10-26 · Analyzed
6.5EPSS 0.009