Vulnerabilities > Codesys > Development System > High

DATE CVE VULNERABILITY TITLE RISK
2023-08-03 CVE-2023-3662 Uncontrolled Search Path Element vulnerability in Codesys Development System
In CODESYS Development System versions from 3.5.17.0 and prior to 3.5.19.20 a vulnerability allows for execution of binaries from the current working directory in the users context .
local
low complexity
codesys CWE-427
7.3
2023-08-03 CVE-2023-3663 Improper Verification of Source of a Communication Channel vulnerability in Codesys Development System
In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to manipulate the content of notifications received via HTTP by the CODESYS notification server.
network
low complexity
codesys CWE-940
8.8
2023-07-28 CVE-2023-3670 Exposure of Resource to Wrong Sphere vulnerability in Codesys Development System and Scripting
In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.
local
low complexity
codesys CWE-668
7.3
2023-03-23 CVE-2022-4224 Insecure Default Initialization of Resource vulnerability in Codesys products
In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.
network
low complexity
codesys CWE-1188
8.8
2022-07-11 CVE-2022-30791 Resource Exhaustion vulnerability in Codesys products
In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections.
network
low complexity
codesys CWE-400
7.5
2022-07-11 CVE-2022-30792 Resource Exhaustion vulnerability in Codesys products
In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections.
network
low complexity
codesys CWE-400
7.5
2022-06-24 CVE-2022-31805 Unprotected Transport of Credentials vulnerability in Codesys products
In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
network
low complexity
codesys CWE-523
7.5
2022-04-07 CVE-2022-22514 Untrusted Pointer Dereference vulnerability in Codesys products
An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request.
network
low complexity
codesys CWE-822
7.1
2022-04-07 CVE-2022-22515 Exposure of Resource to Wrong Sphere vulnerability in Codesys products
A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.
network
low complexity
codesys CWE-668
8.1
2022-04-07 CVE-2022-22516 Incorrect Permission Assignment for Critical Resource vulnerability in Codesys products
The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space.
local
low complexity
codesys CWE-732
7.8