← Back

Codesys

codesys

132 CVEs • 73 products

Products (73)

Click to collapse
Toggle
Hmi Sl
hmi_sl
Hmi
hmi
Safety Sil2
safety_sil2
Gateway
gateway
Plcwinnt
plcwinnt
Control Rte
control_rte
Control Win
control_win
Codesys
codesys
Edge Gateway
edge_gateway
V2 Web Server
v2_web_server
Web Server
web_server
Opc Server
opc_server
Plchandler
plchandler
Linux
linux
Control
control
Visualization
visualization
Targetvisu Sl
targetvisu_sl
Raspberry Pi
raspberry_pi
Eni Server
eni_server
Runtime
runtime
Safety Sil
safety_sil
Ethernetip
ethernetip
Git
git
Profinet
profinet
Opc Da Server
opc_da_server
Control Rte V3
control_rte_v3
Control Win V3
control_win_v3
Hmi V3
hmi_v3
Scripting
scripting

CVEs (132)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Codesys
Wago
28750 8202 Firmware
750 8203 Firmware750 8204 Firmware+25 more
Jun 17, 2026
Oct 26, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.
2Codesys
Wago
28750 8202 Firmware
750 8203 Firmware750 8204 Firmware+25 more
Jun 17, 2026
Oct 26, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.
1Codesys
1Codesys
Jun 17, 2026
Aug 25, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrar...Show more
An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.Show less
1Codesys
1Codesys
Jun 17, 2026
Aug 18, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbit...Show more
An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.Show less
1Codesys
1Codesys
Jun 17, 2026
Aug 18, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to ar...Show more
An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.Show less
1Codesys
1Development System
Jun 17, 2026
Aug 5, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command ex...Show more
A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.Show less
1Codesys
1Ethernetip
Jun 17, 2026
Aug 4, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP stack that is executed by the CODESYS Control runtime system.
1Codesys
1Gateway
Jun 17, 2026
Aug 4, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products and may result in a denial-of-service cond...Show more
In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products and may result in a denial-of-service condition.Show less
1Codesys
7Control
Control RteControl Runtime System Toolkit+4 more
Jun 17, 2026
Aug 3, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.
1Codesys
1Runtime Toolkit
Jun 17, 2026
Aug 3, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
All versions of the CODESYS V3 Runtime Toolkit for VxWorks from version V3.5.8.0 and before version V3.5.17.10 have Improper Handling of Exceptional Conditions.
1Codesys
7Control
Control RteControl Runtime System Toolkit+4 more
Jun 17, 2026
Aug 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
1Codesys
1Development System
Jun 17, 2026
Aug 2, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to ar...Show more
A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.Show less
1Codesys
1Development System
Jun 17, 2026
Aug 2, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Development System 3.5.16. A specially crafted file can lead to arbitrary comma...Show more
A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Development System 3.5.16. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.Show less
1Codesys
1Development System
Jun 17, 2026
Aug 2, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to...Show more
A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.Show less
2Codesys
Wago
29750 8202 Firmware
750 8203 Firmware750 8204 Firmware+26 more
Jun 17, 2026
May 25, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.
2Codesys
Wago
28750 8202 Firmware
750 8203 Firmware750 8204 Firmware+25 more
Jun 17, 2026
May 25, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.
2Codesys
Wago
28750 8202 Firmware
750 8203 Firmware750 8204 Firmware+25 more
Jun 17, 2026
May 25, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.
2Codesys
Wago
28750 8202 Firmware
750 8203 Firmware750 8204 Firmware+25 more
Jun 17, 2026
May 25, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.
2Codesys
Wago
28750 8202 Firmware
750 8203 Firmware750 8204 Firmware+25 more
Jun 17, 2026
May 25, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.
2Codesys
Wago
28750 8202 Firmware
750 8203 Firmware750 8204 Firmware+25 more
Jun 17, 2026
May 25, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.