Remote Target Visu Toolkit
Codesys · 16 CVEs
Codesys Runtime Improper Limitation of a Pathname
Mar 23, 2023
CODESYS: CmpChannelServer, CmpChannelServerEmbedded allow unauthenticated attackers to block all their available commun…
Jul 11, 2022
CODESYS V3: CmpBlkDrvTcp allows unauthenticated attackers to block all its available TCP connections
Jul 11, 2022
Special HTTP(s) Requests can cause a buffer-read causing a crash of the webserver and the runtime system.
Apr 7, 2022
Communication Components in multiple CODESYS products vulnerable to communication channel disruption
Apr 7, 2022
A component of the CODESYS Control runtime system allows read and write access to configuration files
Apr 7, 2022
Untrusted Pointer Dereference in multiple CODESYS products can lead to a DoS.
Apr 7, 2022
Null Pointer Dereference in multiple CODESYS products can lead to a DoS.
Apr 7, 2022
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.
Aug 3, 2021
CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
Aug 3, 2021
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication…
May 3, 2021
CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
Jul 22, 2020
CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.
Mar 26, 2020
CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.
Nov 20, 2019
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requ…
Sep 13, 2019
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requ…
Sep 13, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2018-25048 | Codesys Runtime Improper Limitation of a Pathname | HIGH | 1.02% | Mar 23, 2023 |
| CVE-2022-30792 | CODESYS: CmpChannelServer, CmpChannelServerEmbedded allow unauthenticated attackers to block all their available communication channels | HIGH | 0.89% | Jul 11, 2022 |
| CVE-2022-30791 | CODESYS V3: CmpBlkDrvTcp allows unauthenticated attackers to block all its available TCP connections | HIGH | 0.89% | Jul 11, 2022 |
| CVE-2022-22519 | Special HTTP(s) Requests can cause a buffer-read causing a crash of the webserver and the runtime system. | HIGH | 1.46% | Apr 7, 2022 |
| CVE-2022-22517 | Communication Components in multiple CODESYS products vulnerable to communication channel disruption | HIGH | 1.32% | Apr 7, 2022 |
| CVE-2022-22515 | A component of the CODESYS Control runtime system allows read and write access to configuration files | HIGH | 1.11% | Apr 7, 2022 |
| CVE-2022-22514 | Untrusted Pointer Dereference in multiple CODESYS products can lead to a DoS. | HIGH | 0.89% | Apr 7, 2022 |
| CVE-2022-22513 | Null Pointer Dereference in multiple CODESYS products can lead to a DoS. | MEDIUM | 1.04% | Apr 7, 2022 |
| CVE-2021-36763 | In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties. | HIGH | 1.01% | Aug 3, 2021 |
| CVE-2021-33485 | CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow. | CRITICAL | 1.14% | Aug 3, 2021 |
| CVE-2021-29242 | CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressin… | HIGH | 1.07% | May 3, 2021 |
| CVE-2020-15806 | CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation. | HIGH | 2.05% | Jul 22, 2020 |
| CVE-2020-10245 | CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow. | CRITICAL | 2.50% | Mar 26, 2020 |
| CVE-2019-18858 | CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow. | CRITICAL | 1.94% | Nov 20, 2019 |
| CVE-2019-13548 | CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow… | CRITICAL | 5.81% | Sep 13, 2019 |
| CVE-2019-13532 | CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files out… | HIGH | 3.15% | Sep 13, 2019 |
Showing 1 to 16 of 16 CVEs