Vulnerabilities > Codesys > High

DATE CVE VULNERABILITY TITLE RISK
2023-05-15 CVE-2022-47390 Unspecified vulnerability in Codesys products
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
network
low complexity
codesys
8.8
2023-05-15 CVE-2022-4048 Unspecified vulnerability in Codesys Development System V3
Inadequate Encryption Strength in CODESYS Development System V3 versions prior to V3.5.18.40 allows an unauthenticated local attacker to access and manipulate code of the encrypted boot application.
local
low complexity
codesys
7.7
2023-03-23 CVE-2022-4224 Unspecified vulnerability in Codesys products
In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.
network
low complexity
codesys
8.8
2022-12-26 CVE-2020-12069 Use of Password Hash With Insufficient Computational Effort vulnerability in multiple products
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm.
local
low complexity
pilz codesys festo wago CWE-916
7.8
2022-04-07 CVE-2022-22514 Unspecified vulnerability in Codesys products
An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request.
network
low complexity
codesys
7.1
2022-04-07 CVE-2022-22516 Unspecified vulnerability in Codesys products
The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space.
local
low complexity
codesys
7.8
2022-04-07 CVE-2022-22517 Use of Insufficiently Random Values vulnerability in Codesys products
An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets.
network
low complexity
codesys CWE-330
7.5
2022-04-07 CVE-2022-22519 Unspecified vulnerability in Codesys products
A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system.
network
low complexity
codesys
7.5
2022-02-02 CVE-2022-22510 NULL Pointer Dereference vulnerability in Codesys Profinet 4.2.0.0
Codesys Profinet in version V4.2.0.0 is prone to null pointer dereference that allows a denial of service (DoS) attack of an unauthenticated user via SNMP.
network
low complexity
codesys CWE-476
7.5
2021-12-01 CVE-2021-34599 Unspecified vulnerability in Codesys GIT
Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes.
network
high complexity
codesys
7.4