VendorsCODESYSremote_target_visu_toolkitall versions
Vulnerabilities

CODESYS Remote Target Visu Toolkit

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2020-10245
CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.
Published 2020-03-26 · Modified
10.0EPSS 0.025
CVE-2019-13548
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution.
Published 2019-09-13 · Modified
9.8EPSS 0.058
CVE-2019-18858
CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.
Published 2019-11-20 · Modified
9.8EPSS 0.019
CVE-2021-33485
CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
Published 2021-08-03 · Modified
9.8EPSS 0.011
CVE-2018-25048
Codesys Runtime Improper Limitation of a Pathname
Published 2023-03-23 · Modified
8.8EPSS 0.010
CVE-2022-22515
A component of the CODESYS Control runtime system allows read and write access to configuration files
Published 2022-04-07 · Modified
8.1EPSS 0.011
CVE-2019-13532
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.
Published 2019-09-13 · Modified
7.5EPSS 0.032
CVE-2020-15806
CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
Published 2020-07-22 · Modified
7.5EPSS 0.020
CVE-2022-22519
Special HTTP(s) Requests can cause a buffer-read causing a crash of the webserver and the runtime system.
Published 2022-04-07 · Modified
7.5EPSS 0.015
CVE-2022-22517
Communication Components in multiple CODESYS products vulnerable to communication channel disruption
Published 2022-04-07 · Modified
7.5EPSS 0.013
CVE-2021-29242
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.
Published 2021-05-03 · Modified
7.5EPSS 0.011
CVE-2021-36763
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.
Published 2021-08-03 · Modified
7.5EPSS 0.010
CVE-2022-30791
CODESYS V3: CmpBlkDrvTcp allows unauthenticated attackers to block all its available TCP connections
Published 2022-07-11 · Modified
7.5EPSS 0.009
CVE-2022-30792
CODESYS: CmpChannelServer, CmpChannelServerEmbedded allow unauthenticated attackers to block all their available communication channels
Published 2022-07-11 · Modified
7.5EPSS 0.009
CVE-2022-22514
Untrusted Pointer Dereference in multiple CODESYS products can lead to a DoS.
Published 2022-04-07 · Modified
7.1EPSS 0.009
CVE-2022-22513
Null Pointer Dereference in multiple CODESYS products can lead to a DoS.
Published 2022-04-07 · Modified
6.5EPSS 0.010