Codesys / Gateway
19 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-76992 | Uncontrolled Memory Allocation in CODESYS Gateway Client | HIGH | 8.7 | Sep 30, 2026 |
| CVE-2023-5751 | CODESYS: Development system prone to DoS through exposure of resource to wrong sphere | HIGH | 7.8 | Jun 4, 2024 |
| CVE-2022-30792 | CODESYS: CmpChannelServer, CmpChannelServerEmbedded allow unauthenticated attackers to block all their available communication channels | HIGH | 7.5 | Jul 11, 2022 |
| CVE-2022-30791 | CODESYS V3: CmpBlkDrvTcp allows unauthenticated attackers to block all its available TCP connections | HIGH | 7.5 | Jul 11, 2022 |
| CVE-2022-31805 | Insecure transmission of credentials | HIGH | 7.5 | Jun 24, 2022 |
| CVE-2022-31804 | CODESYS Gateway server prone to denial of service attack due to excessive memory allocation | HIGH | 7.5 | Jun 24, 2022 |
| CVE-2022-31803 | CODESYS Gateway Server V2 prone to Denial of Service Attack | MEDIUM | 5.3 | Jun 24, 2022 |
| CVE-2022-31802 | Partial string comparison in CODESYS gateway server | CRITICAL | 9.8 | Jun 24, 2022 |
| CVE-2022-22517 | Communication Components in multiple CODESYS products vulnerable to communication channel disruption | HIGH | 7.5 | Apr 7, 2022 |
| CVE-2022-22514 | Untrusted Pointer Dereference in multiple CODESYS products can lead to a DoS. | HIGH | 7.1 | Apr 7, 2022 |
| CVE-2022-22513 | Null Pointer Dereference in multiple CODESYS products can lead to a DoS. | MEDIUM | 6.5 | Apr 7, 2022 |
| CVE-2021-36764 | In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affecte… | HIGH | 7.5 | Aug 4, 2021 |
| CVE-2021-29242 | CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressin… | HIGH | 7.3 | May 3, 2021 |
| CVE-2021-29241 | CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS). | HIGH | 7.5 | May 3, 2021 |
| CVE-2020-7052 | CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition. | MEDIUM | 6.5 | Jan 24, 2020 |
| CVE-2019-9009 | An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash. | HIGH | 7.5 | Sep 17, 2019 |
| CVE-2019-9012 | An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication request may cause uncontrolled memory allocations in the affected CODESYS prod… | HIGH | 7.5 | Aug 15, 2019 |
| CVE-2019-9010 | An issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of a communication channel. All variants o… | CRITICAL | 9.8 | Aug 15, 2019 |
| CVE-2018-20026 | Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0. | HIGH | 7.5 | Feb 19, 2019 |
| CVE-2018-20025 | Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0. | HIGH | 7.5 | Feb 19, 2019 |
Showing 1 to 19 of 19 CVEs