CVEs (43)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disgui...Show more |
1Codesys 16Control For Beaglebone Sl Control For Empc A/imx6 SlControl For Iot2000 Sl+13 moreJun 17, 2026 Mar 23, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device. |
1Codesys 19Control For Beaglebone Control For Empc A/imx6Control For Iot2000 Sl+16 moreJun 17, 2026 Jul 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected. |
1Codesys 19Control For Beaglebone Control For Empc A/imx6Control For Iot2000 Sl+16 moreJun 17, 2026 Jul 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected. |
1Codesys 10Development System Edge GatewayGateway+7 moreJun 17, 2026 Jun 24, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected. |
1Codesys 18Control For Beaglebone Sl Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+15 moreJun 17, 2026 Apr 7, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system. |
1Codesys 20Control For Beaglebone Sl Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+17 moreJun 17, 2026 Apr 7, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed. |
1Codesys 4Control Rte Sl Control Rte Sl (for Beckhoff Cx)Control Win Sl+1 moreJun 17, 2026 Apr 7, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space. |
1Codesys 18Control For Beaglebone Sl Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+15 moreJun 17, 2026 Apr 7, 2022 N/A· v4 8.1 HIGH· v3 4.9 MEDIUM· v2 A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products. |
1Codesys 20Control For Beaglebone Sl Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+17 moreJun 17, 2026 Apr 7, 2022 N/A· v4 7.1 HIGH· v3 4.9 MEDIUM· v2 An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither g...Show more |
1Codesys 20Control For Beaglebone Sl Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+17 moreJun 17, 2026 Apr 7, 2022 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash. |
A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command ex...Show more |
A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to ar...Show more |
A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Development System 3.5.16. A specially crafted file can lead to arbitrary comma...Show more |
A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to...Show more |
The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before installation and may be used to install CODESYS packages with malicious content. |
1Codesys 11Control For Beaglebone Sl Control For Empc A/imx6 SlControl For Iot2000 Sl+8 moreJun 17, 2026 May 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS). |
CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries without first checking their validity. |
1Codesys 12Control For Beaglebone Control For Empc A/imx6Control For Iot2000+9 moreJun 17, 2026 May 14, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation. |
1Codesys 10Control For Beaglebone Sl Control For Empc A/imx6 SlControl For Iot2000 Sl+7 moreJun 17, 2026 Aug 15, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication request may cause uncontrolled memory allocations in the affected CODESYS products and may result in a denial-of-service condition. All var...Show more |