Vulnerabilities > Codesys

DATE CVE VULNERABILITY TITLE RISK
2021-05-25 CVE-2021-30188 Out-of-bounds Write vulnerability in Codesys V2 Runtime System SP
CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.
network
low complexity
codesys CWE-787
critical
9.8
2021-05-25 CVE-2021-30189 Out-of-bounds Write vulnerability in Codesys V2 web Server
CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.
network
low complexity
codesys CWE-787
critical
9.8
2021-05-25 CVE-2021-30190 Missing Authentication for Critical Function vulnerability in Codesys V2 web Server
CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.
network
low complexity
codesys CWE-306
critical
9.8
2021-05-25 CVE-2021-30191 Classic Buffer Overflow vulnerability in Codesys V2 web Server
CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.
network
low complexity
codesys CWE-120
7.5
2021-05-25 CVE-2021-30192 Unspecified vulnerability in Codesys V2 web Server
CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.
network
low complexity
codesys
critical
9.8
2021-05-25 CVE-2021-30193 Out-of-bounds Write vulnerability in Codesys V2 web Server
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.
network
low complexity
codesys CWE-787
critical
9.8
2021-05-25 CVE-2021-30194 Out-of-bounds Read vulnerability in Codesys V2 web Server
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.
network
low complexity
codesys CWE-125
critical
9.1
2021-05-25 CVE-2021-30195 Out-of-bounds Read vulnerability in Codesys Plcwinnt and Runtime Toolkit
CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.
network
low complexity
codesys CWE-125
7.5
2021-05-25 CVE-2021-30187 OS Command Injection vulnerability in Codesys Runtime Toolkit 2.4.7.54
CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.
local
low complexity
codesys CWE-78
5.3
2021-05-04 CVE-2021-29240 Unspecified vulnerability in Codesys Development System
The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before installation and may be used to install CODESYS packages with malicious content.
local
low complexity
codesys
7.8