Vulnerability index

Browse CVEs

111 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Control For Beaglebone Sl HIGH 8.8
CVE-2022-47390

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products i…

Fix: 4.8.0.0+
Fix from $1,950 2023-05-15
Development System V3 HIGH 7.7
CVE-2022-4048

Inadequate Encryption Strength in CODESYS Development System V3 versions prior to V3.5.18.40 allows an unauthenticated local attacker to access and m…

Fix: 3.5.18.40+
Fix from $1,950 2023-05-15
Control For Beaglebone Sl HIGH 7.5
CVE-2022-47391

In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from inv…

Fix: 4.8.0.0+
Fix from $1,950 2023-05-15
Control For Beaglebone Sl HIGH 8.8
CVE-2022-47379

An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into me…

Fix: 4.8.0.0+
Fix from $1,950 2023-05-15
Control For Beaglebone Sl HIGH 8.8
CVE-2022-47380

An authenticated remote attacker may use a stack based  out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write …

Fix: 4.8.0.0+
Fix from $1,950 2023-05-15
Control For Beaglebone Sl HIGH 8.8
CVE-2022-47381

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write d…

Fix: 4.8.0.0+
Fix from $1,950 2023-05-15
Control For Beaglebone Sl HIGH 8.8
CVE-2022-47382

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in…

Fix: 4.8.0.0+
Fix from $1,950 2023-05-15
Control For Beaglebone Sl HIGH 8.8
CVE-2022-47383

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products i…

Fix: 4.8.0.0+
Fix from $1,950 2023-05-15
Control For Beaglebone Sl HIGH 8.8
CVE-2022-47384

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in…

Fix: 4.8.0.0+
Fix from $1,950 2023-05-15
Control For Beaglebone Sl HIGH 8.8
CVE-2022-47385

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component of multiple CODESYS products i…

Fix: 4.8.0.0+
Fix from $1,950 2023-05-15
Control For Beaglebone Sl HIGH 8.8
CVE-2022-47386

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products i…

Fix: 4.8.0.0+
Fix from $1,950 2023-05-15
Control For Beaglebone Sl MEDIUM 6.5
CVE-2022-47378

Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated remote attacker may craft spe…

Fix: 4.8.0.0+
Fix from $1,600 2023-05-15
Control For Beaglebone Sl HIGH 8.8
CVE-2022-4224

In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files…

Fix: 4.8.0.0+
Fix from $1,950 2023-03-23
Control For Beaglebone HIGH 8.8
CVE-2018-25048

The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to access and modify a…

Fix: 3.5.12.30+
Fix from $1,950 2023-03-23
Visualization MEDIUM 5.3
CVE-2022-1989

All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to information exposure allowing a remote, unauthenticated atta…

Fix: 4.2.0.0+
Fix from $1,600 2022-08-23
Control For Beaglebone HIGH 7.5
CVE-2022-30791

In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections…

Fix: 4.5.0.0 / 4.6.0.0+
Fix from $1,950 2022-07-11
Control For Beaglebone HIGH 7.5
CVE-2022-30792

In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communicati…

Fix: 4.5.0.0 / 4.6.0.0+
Fix from $1,950 2022-07-11
Opc Da Server MEDIUM 5.5
CVE-2022-1794

The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is visible to all authorized Micro…

Fix: 3.5.18.20+
Fix from $1,600 2022-07-11
Plcwinnt HIGH 8.8
CVE-2022-32143

In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the P…

Fix: 2.4.7.57+
Fix from $1,950 2022-06-24
Plcwinnt HIGH 8.1
CVE-2022-32142

Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset…

Fix: 2.4.7.57+
Fix from $1,950 2022-06-24
Plcwinnt MEDIUM 6.5
CVE-2022-32141

Multiple CODESYS Products are prone to a buffer over read. A low privileged remote attacker may craft a request with an invalid offset, which can cau…

Fix: 2.4.7.57+
Fix from $1,600 2022-06-24
Gateway CRITICAL 9.8
CVE-2022-31802

In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway p…

Fix: 2.3.9.38+
Fix from $2,300 2022-06-24
Plcwinnt CRITICAL 9.8
CVE-2022-31806

In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no informatio…

Fix: 2.4.7.57+
Fix from $2,300 2022-06-24
Plcwinnt HIGH 8.8
CVE-2022-32137

In multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause a heap-based buffer overflow, resulting in a deni…

Fix: 2.4.7.57+
Fix from $1,950 2022-06-24
Plcwinnt HIGH 8.8
CVE-2022-32138

In multiple CODESYS products, a remote attacker may craft a request which may cause an unexpected sign extension, resulting in a denial-of-service co…

Fix: 2.4.7.57+
Fix from $1,950 2022-06-24
Plcwinnt HIGH 8.1
CVE-2022-1965

Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processe…

Fix: 2.4.7.57+
Fix from $1,950 2022-06-24
Gateway HIGH 7.5
CVE-2022-31804

The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated attacker may allocate an arbi…

Fix: 2.3.9.38+
Fix from $1,950 2022-06-24
Development System HIGH 7.5
CVE-2022-31805

In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers u…

Fix: 2.3.9.38 / 2.3.9.69+
Fix from $1,950 2022-06-24
Plcwinnt MEDIUM 6.5
CVE-2022-32136

In multiple CODESYS products, a low privileged remote attacker may craft a request that cause a read access to an uninitialized pointer, resulting in…

Fix: 2.4.7.57+
Fix from $1,600 2022-06-24
Plcwinnt MEDIUM 6.5
CVE-2022-32139

In multiple CODESYS products, a low privileged remote attacker may craft a request, which cause an out-of-bounds read, resulting in a denial-of-servi…

Fix: 2.4.7.57+
Fix from $1,600 2022-06-24