Codesys
codesys
132 CVEs • 73 products
Products (73)
Click to collapseToggle
Products (73)
Click to collapse
CVEs (132)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Codesys 17Control For Beaglebone Sl Control For Empc A/imx6 SlControl For Iot2000 Sl+14 moreJun 17, 2026 May 15, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, mem...Show more |
1Codesys 17Control For Beaglebone Sl Control For Empc A/imx6 SlControl For Iot2000 Sl+14 moreJun 17, 2026 May 15, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, me...Show more |
1Codesys 17Control For Beaglebone Sl Control For Empc A/imx6 SlControl For Iot2000 Sl+14 moreJun 17, 2026 May 15, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwritin...Show more |
1Codesys 17Control For Beaglebone Sl Control For Empc A/imx6 SlControl For Iot2000 Sl+14 moreJun 17, 2026 May 15, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated remote attacker may craft specific requests that use the vulnerability leading to a denial-of-servic...Show more |
1Codesys 14Control For Beaglebone Sl Control For Empc A/imx6 SlControl For Iot2000 Sl+11 moreJun 17, 2026 May 15, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block consecutive logins of a specific type. |
1Codesys 16Control For Beaglebone Sl Control For Empc A/imx6 SlControl For Iot2000 Sl+13 moreJun 17, 2026 Mar 23, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device. |
1Codesys 15Control For Beaglebone Control For Empc A/imx6Control For Iot2000+12 moreNov 21, 2024 Mar 23, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to access and modify all system files as well as DoS the device. |
4Codesys FestoPilz+1 more64750 8100 Firmware 750 8101 Firmware750 8102 Firmware+61 moreJun 17, 2026 Dec 26, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local a...Show more |
All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to information exposure allowing a remote, unauthenticated attacker to enumerate valid users. |
1Codesys 19Control For Beaglebone Control For Empc A/imx6Control For Iot2000 Sl+16 moreJun 17, 2026 Jul 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected. |
1Codesys 19Control For Beaglebone Control For Empc A/imx6Control For Iot2000 Sl+16 moreJun 17, 2026 Jul 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected. |
The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is visible to all authorized Microsoft Windows users of the system. |
1Codesys 2Plcwinnt Runtime ToolkitJun 17, 2026 Jun 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the PLC. All requests are processed on the controller only if no level 1 pas...Show more |
1Codesys 2Plcwinnt Runtime ToolkitJun 17, 2026 Jun 24, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset, which can cause an out-of-bounds read or write access, resulting in d...Show more |
1Codesys 2Plcwinnt Runtime ToolkitJun 17, 2026 Jun 24, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Multiple CODESYS Products are prone to a buffer over read. A low privileged remote attacker may craft a request with an invalid offset, which can cause an internal buffer over-read, resulting in a denial-of-service condi...Show more |
1Codesys 2Plcwinnt Runtime ToolkitJun 17, 2026 Jun 24, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Multiple CODESYS products are affected to a buffer overflow.A low privileged remote attacker may craft a request, which can cause a buffer copy without checking the size of the service, resulting in a denial-of-service c...Show more |
1Codesys 2Plcwinnt Runtime ToolkitJun 17, 2026 Jun 24, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In multiple CODESYS products, a low privileged remote attacker may craft a request, which cause an out-of-bounds read, resulting in a denial-of-service condition. User Interaction is not required. |
1Codesys 2Plcwinnt Runtime ToolkitJun 17, 2026 Jun 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In multiple CODESYS products, a remote attacker may craft a request which may cause an unexpected sign extension, resulting in a denial-of-service condition or memory overwrite. |
1Codesys 2Plcwinnt Runtime ToolkitJun 17, 2026 Jun 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause a heap-based buffer overflow, resulting in a denial-of-service condition or memory overwrite. User interaction is not re...Show more |
1Codesys 2Plcwinnt Runtime ToolkitJun 17, 2026 Jun 24, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In multiple CODESYS products, a low privileged remote attacker may craft a request that cause a read access to an uninitialized pointer, resulting in a denial-of-service. User interaction is not required. |