VendorsCODESYSruntime_toolkitall versions
Vulnerabilities

CODESYS Runtime Toolkit

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

23CVEs
CVE-2022-31806
Insecure default settings in CODESYS Runtime Toolkit 32 bit full and CODESYS PLCWinNT
Published 2022-06-24 · Modified
9.8EPSS 0.012
CVE-2022-32137
CODESYS Runtime System prone to heap based buffer overflow
Published 2022-06-24 · Modified
8.8EPSS 0.014
CVE-2022-32143
CODESYS runtime system prone to directory acces
Published 2022-06-24 · Modified
8.8EPSS 0.012
CVE-2022-32138
CODESYS runtime system prone to denial of service due to Unexpected Sign Extension
Published 2022-06-24 · Modified
8.8EPSS 0.012
CVE-2023-6357
OS Command Injection in multiple CODESYS products
Published 2023-12-05 · Modified
8.8EPSS 0.010
CVE-2022-4224
CODESYS: Exposure of Resource to Wrong Sphere in CODESYS V3
Published 2023-03-23 · Modified
8.8EPSS 0.009
CVE-2019-9013
An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the following CODESYS V3 products in all versions containing the CmpUserMgr component are affected regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS V3 Simulation Runtime (part of the CODESYS Development System), CODESYS Control V3 Runtime System Toolkit, CODESYS HMI V3.
Published 2019-08-15 · Modified
8.8EPSS 0.003
CVE-2022-1965
CODESYS runtime system prone to file deletion due to improper error handling
Published 2022-06-24 · Modified
8.1EPSS 0.011
CVE-2022-32142
CODESYS runtime system prone to denial of service due to use of out of range pointer
Published 2022-06-24 · Modified
8.1EPSS 0.011
CVE-2021-34595
CODESYS V2 runtime: out-of-bounds read or write access may result in denial-of-service
Published 2021-10-26 · Analyzed
8.1EPSS 0.009
CVE-2021-30186
CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.
Published 2021-05-25 · Analyzed
7.5EPSS 0.074
CVE-2021-30195
CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.
Published 2021-05-25 · Analyzed
7.5EPSS 0.072
CVE-2021-34593
CODESYS V2 runtime: unauthenticated invalid requests may result in denial-of-service
Published 2021-10-26 · Analyzed
7.5EPSS 0.027
CVE-2022-31805
Insecure transmission of credentials
Published 2022-06-24 · Modified
7.5EPSS 0.010
CVE-2021-33486
All versions of the CODESYS V3 Runtime Toolkit for VxWorks from version V3.5.8.0 and before version V3.5.17.10 have Improper Handling of Exceptional Conditions.
Published 2021-08-03 · Modified
7.5EPSS 0.010
CVE-2025-41738
CODESYS Control - Invalid type usage in visualization
Published 2025-12-01 · Analyzed
7.5EPSS 0.004
CVE-2019-19789
3S-Smart CODESYS SP Realtime NT before V2.3.7.28, CODESYS Runtime Toolkit 32 bit full before V2.4.7.54, and CODESYS PLCWinNT before V2.4.7.54 allow a NULL pointer dereference.
Published 2019-12-20 · Modified
6.5EPSS 0.012
CVE-2022-32140
CODESYS runtime system prone to denial of service due to buffer copy
Published 2022-06-24 · Modified
6.5EPSS 0.010
CVE-2022-32136
Codesys runtime systems: Access of uninitialised pointer lead to denial of service.
Published 2022-06-24 · Modified
6.5EPSS 0.010
CVE-2022-32139
CODESYS runtime system prone to denial of service due to out of bounds read
Published 2022-06-24 · Modified
6.5EPSS 0.010
CVE-2022-32141
CODESYS runtime system prone to denial of service due to buffer over read
Published 2022-06-24 · Modified
6.5EPSS 0.010
CVE-2021-34596
CODESYS V2 runtime: Access of Uninitialized Pointer may result in denial-of-service
Published 2021-10-26 · Analyzed
6.5EPSS 0.009
CVE-2021-30187
CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.
Published 2021-05-25 · Analyzed
5.3EPSS 0.003