Vulnerabilities > Codesys > Plcwinnt > High

DATE CVE VULNERABILITY TITLE RISK
2021-10-26 CVE-2021-34595 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Codesys Plcwinnt and Runtime Toolkit
A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.
network
low complexity
codesys CWE-119
8.1
2021-05-25 CVE-2021-30186 Out-of-bounds Write vulnerability in Codesys Plcwinnt and Runtime Toolkit
CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.
network
low complexity
codesys CWE-787
7.5
2021-05-25 CVE-2021-30195 Out-of-bounds Read vulnerability in Codesys Plcwinnt and Runtime Toolkit
CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.
network
low complexity
codesys CWE-125
7.5