Codesys
codesys
132 CVEs • 73 products
Products (73)
Click to collapseToggle
Products (73)
Click to collapse
CVEs (132)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Codesys 2Plcwinnt Runtime ToolkitJun 17, 2026 Jun 24, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password...Show more |
1Codesys 10Development System Edge GatewayGateway+7 moreJun 17, 2026 Jun 24, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected. |
The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated attacker may allocate an arbitrary amount of memory, which may lead to a crash of the Gateway due to...Show more |
In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all available TCP connections and prevent legitimate users or clients from estab...Show more |
In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small p...Show more |
1Codesys 2Plcwinnt Runtime ToolkitJun 17, 2026 Jun 24, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the req...Show more |
1Codesys 18Control For Beaglebone Sl Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+15 moreJun 17, 2026 Apr 7, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system. |
1Codesys 10Control For Beaglebone Sl Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+7 moreJun 17, 2026 Apr 7, 2022 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymous access to components part of the applied security policy. |
1Codesys 20Control For Beaglebone Sl Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+17 moreJun 17, 2026 Apr 7, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed. |
1Codesys 4Control Rte Sl Control Rte Sl (for Beckhoff Cx)Control Win Sl+1 moreJun 17, 2026 Apr 7, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space. |
1Codesys 18Control For Beaglebone Sl Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+15 moreJun 17, 2026 Apr 7, 2022 N/A· v4 8.1 HIGH· v3 4.9 MEDIUM· v2 A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products. |
1Codesys 20Control For Beaglebone Sl Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+17 moreJun 17, 2026 Apr 7, 2022 N/A· v4 7.1 HIGH· v3 4.9 MEDIUM· v2 An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither g...Show more |
1Codesys 20Control For Beaglebone Sl Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+17 moreJun 17, 2026 Apr 7, 2022 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash. |
Codesys Profinet in version V4.2.0.0 is prone to null pointer dereference that allows a denial of service (DoS) attack of an unauthenticated user via SNMP. |
Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes. CODESYS Git does not implement certificate validation by default, so it does not verify that the server prov...Show more |
2Codesys Wago30750 8202 Firmware 750 8203 Firmware750 8204 Firmware+27 moreJun 17, 2026 Oct 26, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition. |
2Codesys Wago30750 8202 Firmware 750 8203 Firmware750 8204 Firmware+27 moreJun 17, 2026 Oct 26, 2021 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or loc...Show more |
2Codesys Wago15750 8202 Firmware 750 8203 Firmware750 8204 Firmware+12 moreJun 17, 2026 Oct 26, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory...Show more |
2Codesys Wago28750 8202 Firmware 750 8203 Firmware750 8204 Firmware+25 moreJun 17, 2026 Oct 26, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the CODESYS web server and may result in a denial-of-service condition. |
2Codesys Wago28750 8202 Firmware 750 8203 Firmware750 8204 Firmware+25 moreJun 17, 2026 Oct 26, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur...Show more |