← Back

Codesys

codesys

132 CVEs • 73 products

Products (73)

Click to collapse
Toggle
Hmi Sl
hmi_sl
Hmi
hmi
Safety Sil2
safety_sil2
Gateway
gateway
Plcwinnt
plcwinnt
Control Rte
control_rte
Control Win
control_win
Codesys
codesys
Edge Gateway
edge_gateway
V2 Web Server
v2_web_server
Web Server
web_server
Opc Server
opc_server
Plchandler
plchandler
Linux
linux
Control
control
Visualization
visualization
Targetvisu Sl
targetvisu_sl
Raspberry Pi
raspberry_pi
Eni Server
eni_server
Runtime
runtime
Safety Sil
safety_sil
Ethernetip
ethernetip
Git
git
Profinet
profinet
Opc Da Server
opc_da_server
Control Rte V3
control_rte_v3
Control Win V3
control_win_v3
Hmi V3
hmi_v3
Scripting
scripting

CVEs (132)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Codesys
14Control For Beaglebone
Control For Empc A/imx6Control For Iot2000+11 more
Jun 17, 2026
Sep 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash.
1Codesys
10Control For Beaglebone
Control For Empc A/imx6Control For Iot2000+7 more
Jun 17, 2026
Sep 17, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over the runtime.
1Codesys
13Control For Beaglebone
Control For Empc A/imx6Control For Iot2000+10 more
Jun 17, 2026
Sep 13, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code...Show more
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution.Show less
1Codesys
13Control For Beaglebone
Control For Empc A/imx6Control For Iot2000+10 more
Jun 17, 2026
Sep 13, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.
1Codesys
10Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+7 more
Jun 17, 2026
Aug 15, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication request may cause uncontrolled memory allocations in the affected CODESYS products and may result in a denial-of-service condition. All var...Show more
An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication request may cause uncontrolled memory allocations in the affected CODESYS products and may result in a denial-of-service condition. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control V3 Runtime System Toolkit, CODESYS Gateway V3, CODESYS V3 Development System.Show less
1Codesys
10Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+7 more
Jun 17, 2026
Aug 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of a communication channel. All variants of the following CODESYS V3 products in all versions prior to...Show more
An issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of a communication channel. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control V3 Runtime System Toolkit, CODESYS Gateway V3, CODESYS V3 Development System.Show less
1Codesys
12Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+9 more
Jun 17, 2026
Aug 15, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the follow...Show more
An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the following CODESYS V3 products in all versions containing the CmpUserMgr component are affected regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS V3 Simulation Runtime (part of the CODESYS Development System), CODESYS Control V3 Runtime System Toolkit, CODESYS HMI V3.Show less
1Codesys
18Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+15 more
Nov 21, 2024
Feb 19, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0.
1Codesys
15Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+12 more
Nov 21, 2024
Feb 19, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.
1Codesys
12Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+9 more
Nov 21, 2024
Jan 29, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device...Show more
In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials.Show less
1Codesys
1Web Server
May 13, 2026
May 19, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An Arbitrary File Upload issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affe...Show more
An Arbitrary File Upload issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2.3 and prior. A specially crafted web server request may allow the upload of arbitrary files (with a dangerous type) to the CODESYS Web Server without authorization which may allow remote code execution.Show less
1Codesys
1Web Server
May 13, 2026
May 19, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Stack Buffer Overflow issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affec...Show more
A Stack Buffer Overflow issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2.3 and prior. A malicious user could overflow the stack buffer by providing overly long strings to functions that handle the XML. Because the function does not verify string size before copying to memory, the attacker may then be able to crash the application or run arbitrary code.Show less