Vulnerability index

Browse CVEs

111 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2022-32140 Multiple CODESYS products are affected to a buffer overflow.A low privileged remote attacker may craft a request, which can cause a buffer copy witho… Plcwinnt 2.4.7.57+ Fix from $1,6002022-06-24 MEDIUM 5.3 CVE-2022-31803 In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all avail… Gateway 2.3.9.38+ Fix from $1,6002022-06-24 HIGH 8.1 CVE-2022-22515 A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read an… Control For Beaglebone Sl 4.5.0.0+ Fix from $1,9502022-04-07 HIGH 7.8 CVE-2022-22516 The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory spac… Control Rte Sl 3.5.18.0+ Fix from $1,9502022-04-07 HIGH 7.5 CVE-2022-22517 An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting… Control For Beaglebone Sl 4.5.0.0+ Fix from $1,9502022-04-07 HIGH 7.5 CVE-2022-22519 A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserve… Control For Beaglebone Sl 4.5.0.0+ Fix from $1,9502022-04-07 HIGH 7.1 CVE-2022-22514 An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overw… Control For Beaglebone Sl 4.5.0.0+ Fix from $1,9502022-04-07 MEDIUM 6.5 CVE-2022-22513 An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a … Control For Beaglebone Sl 4.5.0.0+ Fix from $1,6002022-04-07 MEDIUM 6.5 CVE-2022-22518 A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymous access to components part o… Control For Beaglebone Sl 4.5.0.0+ Fix from $1,6002022-04-07 HIGH 7.5 CVE-2022-22510 Codesys Profinet in version V4.2.0.0 is prone to null pointer dereference that allows a denial of service (DoS) attack of an unauthenticated user via… Profinet Mitigation only Fix from $1,9502022-02-02 HIGH 7.4 CVE-2021-34599 Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes. CODESYS Git does not implement certif… Git 1.1.0.0+ Fix from $1,9502021-12-01 HIGH 7.8 CVE-2021-21869 An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development … Codesys Patch available Fix from $1,9502021-08-25 HIGH 7.8 CVE-2021-21867 An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Develo… Codesys Patch available Fix from $1,9502021-08-18 HIGH 7.8 CVE-2021-21868 An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Developme… Codesys Patch available Fix from $1,9502021-08-18 HIGH 7.8 CVE-2021-21863 A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.1… Development System Patch available Fix from $1,9502021-08-05 HIGH 7.5 CVE-2021-36764 In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in t… Gateway 3.5.17.10+ Fix from $1,9502021-08-04 HIGH 7.5 CVE-2021-36765 In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP sta… Ethernetip 4.1.0.0+ Fix from $1,9502021-08-04 CRITICAL 9.8 CVE-2021-33485 CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow. Control 3.5.17.10 / 4.2.0.0+ Fix from $2,3002021-08-03 HIGH 7.5 CVE-2021-33486 All versions of the CODESYS V3 Runtime Toolkit for VxWorks from version V3.5.8.0 and before version V3.5.17.10 have Improper Handling of Exceptional … Runtime Toolkit 3.5.17.10+ Fix from $1,9502021-08-03 HIGH 7.5 CVE-2021-36763 In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties. Control 3.5.17.10 / 4.2.0.0+ Fix from $1,9502021-08-03 HIGH 7.8 CVE-2021-21866 A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Develo… Development System Patch available Fix from $1,9502021-08-02 HIGH 7.8 CVE-2021-21864 A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Dev… Development System Patch available Fix from $1,9502021-08-02 HIGH 7.8 CVE-2021-21865 A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Developm… Development System Patch available Fix from $1,9502021-08-02 HIGH 7.8 CVE-2021-29240 The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before installation and may be used to in… Development System 3.5.17.0+ Fix from $1,9502021-05-04 HIGH 8.8 CVE-2021-29238 CODESYS Automation Server before 1.16.0 allows cross-site request forgery (CSRF). Automation Server 1.16.0+ Fix from $1,9502021-05-03 HIGH 7.8 CVE-2021-29239 CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries without first checking their val… Development System 3.5.17.0+ Fix from $1,9502021-05-03 HIGH 7.5 CVE-2021-29241 CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS). Control For Beaglebone Sl 3.5.16.0 / 3.5.16.70+ Fix from $1,9502021-05-03 HIGH 7.3 CVE-2021-29242 CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's… Control For Beaglebone Sl 4.1.0.0+ Fix from $1,9502021-05-03 HIGH 7.5 CVE-2020-15806 CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation. Control For Beaglebone 3.5.16.10+ Fix from $1,9502020-07-22 MEDIUM 6.5 CVE-2020-12068 An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege esc… Control For Beaglebone 3.5.16.0+ Fix from $1,6002020-05-14