← Back

Codesys

codesys

132 CVEs • 73 products

Products (73)

Click to collapse
Toggle
Hmi Sl
hmi_sl
Hmi
hmi
Safety Sil2
safety_sil2
Gateway
gateway
Plcwinnt
plcwinnt
Control Rte
control_rte
Control Win
control_win
Codesys
codesys
Edge Gateway
edge_gateway
V2 Web Server
v2_web_server
Web Server
web_server
Opc Server
opc_server
Plchandler
plchandler
Linux
linux
Control
control
Visualization
visualization
Targetvisu Sl
targetvisu_sl
Raspberry Pi
raspberry_pi
Eni Server
eni_server
Runtime
runtime
Safety Sil
safety_sil
Ethernetip
ethernetip
Git
git
Profinet
profinet
Opc Da Server
opc_da_server
Control Rte V3
control_rte_v3
Control Win V3
control_win_v3
Hmi V3
hmi_v3
Scripting
scripting

CVEs (132)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Codesys
2Plcwinnt
Runtime Toolkit
Jun 17, 2026
Jun 24, 2022
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password...Show more
In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the controller.Show less
1Codesys
10Development System
Edge GatewayGateway+7 more
Jun 17, 2026
Jun 24, 2022
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
1Codesys
1Gateway
Jun 17, 2026
Jun 24, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated attacker may allocate an arbitrary amount of memory, which may lead to a crash of the Gateway due to...Show more
The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated attacker may allocate an arbitrary amount of memory, which may lead to a crash of the Gateway due to an out-of-memory condition.Show less
1Codesys
1Gateway
Jun 17, 2026
Jun 24, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all available TCP connections and prevent legitimate users or clients from estab...Show more
In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all available TCP connections and prevent legitimate users or clients from establishing a new connection to the CODESYS Gateway Server V2. Existing connections are not affected and therefore remain intact.Show less
1Codesys
1Gateway
Jun 17, 2026
Jun 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small p...Show more
In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer real CODESYS Gateway password.Show less
1Codesys
2Plcwinnt
Runtime Toolkit
Jun 17, 2026
Jun 24, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the req...Show more
Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required.Show less
1Codesys
18Control For Beaglebone Sl
Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+15 more
Jun 17, 2026
Apr 7, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system.
1Codesys
10Control For Beaglebone Sl
Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+7 more
Jun 17, 2026
Apr 7, 2022
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymous access to components part of the applied security policy.
1Codesys
20Control For Beaglebone Sl
Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+17 more
Jun 17, 2026
Apr 7, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.
1Codesys
4Control Rte Sl
Control Rte Sl (for Beckhoff Cx)Control Win Sl+1 more
Jun 17, 2026
Apr 7, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space.
1Codesys
18Control For Beaglebone Sl
Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+15 more
Jun 17, 2026
Apr 7, 2022
N/A· v4
8.1 HIGH· v3
4.9 MEDIUM· v2
A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.
1Codesys
20Control For Beaglebone Sl
Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+17 more
Jun 17, 2026
Apr 7, 2022
N/A· v4
7.1 HIGH· v3
4.9 MEDIUM· v2
An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither g...Show more
An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed, this results in a crash.Show less
1Codesys
20Control For Beaglebone Sl
Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+17 more
Jun 17, 2026
Apr 7, 2022
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.
1Codesys
1Profinet
Jun 17, 2026
Feb 2, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Codesys Profinet in version V4.2.0.0 is prone to null pointer dereference that allows a denial of service (DoS) attack of an unauthenticated user via SNMP.
1Codesys
1Git
Jun 17, 2026
Dec 1, 2021
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes. CODESYS Git does not implement certificate validation by default, so it does not verify that the server prov...Show more
Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes. CODESYS Git does not implement certificate validation by default, so it does not verify that the server provides a valid and trusted HTTPS certificate. Since the certificate of the server to which the connection is made is not properly verified, the server connection is vulnerable to a man-in-the-middle attack.Show less
2Codesys
Wago
30750 8202 Firmware
750 8203 Firmware750 8204 Firmware+27 more
Jun 17, 2026
Oct 26, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition.
2Codesys
Wago
30750 8202 Firmware
750 8203 Firmware750 8204 Firmware+27 more
Jun 17, 2026
Oct 26, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or loc...Show more
A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.Show less
2Codesys
Wago
15750 8202 Firmware
750 8203 Firmware750 8204 Firmware+12 more
Jun 17, 2026
Oct 26, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory...Show more
In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.Show less
2Codesys
Wago
28750 8202 Firmware
750 8203 Firmware750 8204 Firmware+25 more
Jun 17, 2026
Oct 26, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the CODESYS web server and may result in a denial-of-service condition.
2Codesys
Wago
28750 8202 Firmware
750 8203 Firmware750 8204 Firmware+25 more
Jun 17, 2026
Oct 26, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur...Show more
In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation.Show less