← Back

Codesys

codesys

132 CVEs • 73 products

Products (73)

Click to collapse
Toggle
Hmi Sl
hmi_sl
Hmi
hmi
Safety Sil2
safety_sil2
Gateway
gateway
Plcwinnt
plcwinnt
Control Rte
control_rte
Control Win
control_win
Codesys
codesys
Edge Gateway
edge_gateway
V2 Web Server
v2_web_server
Web Server
web_server
Opc Server
opc_server
Plchandler
plchandler
Linux
linux
Control
control
Visualization
visualization
Targetvisu Sl
targetvisu_sl
Raspberry Pi
raspberry_pi
Eni Server
eni_server
Runtime
runtime
Safety Sil
safety_sil
Ethernetip
ethernetip
Git
git
Profinet
profinet
Opc Da Server
opc_da_server
Control Rte V3
control_rte_v3
Control Win V3
control_win_v3
Hmi V3
hmi_v3
Scripting
scripting

CVEs (132)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Codesys
Wago
28750 8202 Firmware
750 8203 Firmware750 8204 Firmware+25 more
Jun 17, 2026
May 25, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.
2Codesys
Wago
28750 8202 Firmware
750 8203 Firmware750 8204 Firmware+25 more
Jun 17, 2026
May 25, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.
2Codesys
Wago
29750 8202 Firmware
750 8203 Firmware750 8204 Firmware+26 more
Jun 17, 2026
May 25, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.
2Codesys
Wago
28750 8202 Firmware
750 8203 Firmware750 8204 Firmware+25 more
Jun 17, 2026
May 25, 2021
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.
1Codesys
1Development System
Jun 17, 2026
May 4, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before installation and may be used to install CODESYS packages with malicious content.
1Codesys
22Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+19 more
Jun 17, 2026
May 3, 2021
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level co...Show more
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.Show less
1Codesys
11Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+8 more
Jun 17, 2026
May 3, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).
1Codesys
1Development System
Jun 17, 2026
May 3, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries without first checking their validity.
1Codesys
1Automation Server
Jun 17, 2026
May 3, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CODESYS Automation Server before 1.16.0 allows cross-site request forgery (CSRF).
1Codesys
16Control For Beaglebone
Control For Empc A/imx6Control For Iot2000+13 more
Jun 17, 2026
Jul 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
1Codesys
12Control For Beaglebone
Control For Empc A/imx6Control For Iot2000+9 more
Jun 17, 2026
May 14, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.
1Codesys
1Runtime
Jun 17, 2026
May 7, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable code execution vulnerability exists in the PLC_Task functionality of 3S-Smart Software Solutions GmbH CODESYS Runtime 3.5.14.30. A specially crafted network request can cause remote code execution. An atta...Show more
An exploitable code execution vulnerability exists in the PLC_Task functionality of 3S-Smart Software Solutions GmbH CODESYS Runtime 3.5.14.30. A specially crafted network request can cause remote code execution. An attacker can send a malicious packet to trigger this vulnerability.Show less
1Codesys
1Codesys
Jun 17, 2026
Mar 26, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S-Smart Software Solutions CODESYS GatewayService. A specially crafted packet can cause a large memcpy, resulting in an a...Show more
An exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S-Smart Software Solutions CODESYS GatewayService. A specially crafted packet can cause a large memcpy, resulting in an access violation and termination of the process. An attacker can send a packet to a device running the GatewayService.exe to trigger this vulnerability. All variants of the CODESYS V3 products in all versions prior V3.5.16.10 containing the CmpRouter or CmpRouterEmbedded component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PLCnext, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS Control V3 Runtime System Toolkit, CODESYS V3 Embedded Target Visu Toolkit, CODESYS V3 Remote Target Visu Toolkit, CODESYS V3 Safety SIL2, CODESYS Edge Gateway V3, CODESYS Gateway V3, CODESYS HMI V3, CODESYS OPC Server V3, CODESYS PLCHandler SDK, CODESYS V3 Simulation Runtime (part of the CODESYS Development System).Show less
1Codesys
14Control For Beaglebone
Control For Empc A/imx6Control For Iot2000+11 more
Jun 17, 2026
Mar 26, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.
1Codesys
15Control For Beaglebone
Control For Empc A/imx6Control For Iot2000+12 more
Jun 17, 2026
Jan 24, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.
1Codesys
3Plcwinnt
Runtime ToolkitSp Realtime Nt
Jun 17, 2026
Dec 20, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
3S-Smart CODESYS SP Realtime NT before V2.3.7.28, CODESYS Runtime Toolkit 32 bit full before V2.4.7.54, and CODESYS PLCWinNT before V2.4.7.54 allow a NULL pointer dereference.
1Codesys
14Control For Beaglebone
Control For Empc A/imx6Control For Iot2000+11 more
Jun 17, 2026
Nov 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.
1Codesys
2Codesys
Eni Server
Jun 17, 2026
Oct 25, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CODESYS V2.3 ENI server up to V3.2.2.24 has a Buffer Overflow.
1Codesys
1Codesys
Jun 17, 2026
Sep 17, 2019
N/A· v4
8.6 HIGH· v3
6.8 MEDIUM· v2
3S-Smart Software Solutions GmbH CODESYS V3 Library Manager, all versions prior to 3.5.16.0, allows the system to display active library content without checking its validity, which may allow the contents of manipulated...Show more
3S-Smart Software Solutions GmbH CODESYS V3 Library Manager, all versions prior to 3.5.16.0, allows the system to display active library content without checking its validity, which may allow the contents of manipulated libraries to be displayed or executed. The issue also exists for source libraries, but 3S-Smart Software Solutions GmbH strongly recommends distributing compiled libraries only.Show less
1Codesys
10Control For Beaglebone
Control For Empc A/imx6Control For Iot2000+7 more
Jun 17, 2026
Sep 17, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
3S-Smart Software Solutions GmbH CODESYS V3 OPC UA Server, all versions 3.5.11.0 to 3.5.15.0, allows an attacker to send crafted requests from a trusted OPC UA client that cause a NULL pointer dereference, which may trig...Show more
3S-Smart Software Solutions GmbH CODESYS V3 OPC UA Server, all versions 3.5.11.0 to 3.5.15.0, allows an attacker to send crafted requests from a trusted OPC UA client that cause a NULL pointer dereference, which may trigger a denial-of-service condition.Show less