← Back

3ssoftware

4 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Codesys
codesys

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
13ssoftware
1Codesys
Apr 29, 2026
Jan 10, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The CmbWebserver.dll module of the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to create arbitrary directories under the web root by specifying a non-existent directory using \ (backslash) chara...Show more
The CmbWebserver.dll module of the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to create arbitrary directories under the web root by specifying a non-existent directory using \ (backslash) characters in an HTTP GET request.Show less
13ssoftware
1Codesys
Apr 29, 2026
Dec 25, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The CmpWebServer.dll module in the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a crafted Content-Length in an HTTP POST or (2) an...Show more
The CmpWebServer.dll module in the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a crafted Content-Length in an HTTP POST or (2) an invalid HTTP request method.Show less
13ssoftware
1Codesys
Apr 29, 2026
Dec 25, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in the GatewayService component in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to execute arbitrary code via a large size value in the packet header, which triggers a heap-based buffer overflow.
13ssoftware
1Codesys
Apr 29, 2026
Dec 25, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, allows remote attackers to execute arbitrary code via a long...Show more
Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, allows remote attackers to execute arbitrary code via a long URI to TCP port 8080.Show less