CVEs (28)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Codesys 18Control For Beaglebone Sl Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+15 moreJun 17, 2026 Apr 7, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system. |
1Codesys 20Control For Beaglebone Sl Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+17 moreJun 17, 2026 Apr 7, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed. |
1Codesys 4Control Rte Sl Control Rte Sl (for Beckhoff Cx)Control Win Sl+1 moreJun 17, 2026 Apr 7, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space. |
1Codesys 18Control For Beaglebone Sl Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+15 moreJun 17, 2026 Apr 7, 2022 N/A· v4 8.1 HIGH· v3 4.9 MEDIUM· v2 A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products. |
1Codesys 20Control For Beaglebone Sl Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+17 moreJun 17, 2026 Apr 7, 2022 N/A· v4 7.1 HIGH· v3 4.9 MEDIUM· v2 An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither g...Show more |
1Codesys 20Control For Beaglebone Sl Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+17 moreJun 17, 2026 Apr 7, 2022 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash. |
1Codesys 18Control For Beaglebone Sl Control For Empc A/imx6 SlControl For Iot2000 Sl+15 moreNov 21, 2024 Feb 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0. |
1Codesys 15Control For Beaglebone Sl Control For Empc A/imx6 SlControl For Iot2000 Sl+12 moreNov 21, 2024 Feb 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0. |