cbcvebase.

Codesys Control For Linux Arm Sl vulnerabilities

10 known vulnerabilities affecting codesys/codesys_control_for_linux_arm_sl.

Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH8MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2025-41660P2HIGHCVSS 8.8≥ 0.0.0, < 4.21.0.02026-03-24
CVE-2025-41660 [HIGH] CWE-669 CVE-2025-41660: A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.
nvd
CVE-2023-6357P3HIGHCVSS 8.8fixed in 4.11.0.02023-12-05
CVE-2023-6357 [HIGH] CWE-78 CVE-2023-6357: A low-privileged remote attacker could exploit the vulnerability and inject additional system comman A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.
nvd
CVE-2026-8046P3HIGHCVSS 8.1≥ 3.0.0.0, < 4.21.0.02026-05-26
CVE-2026-8046 [HIGH] CWE-863 CVE-2026-8046: The affected products insufficiently verify authorization when deleting user accounts. An authentica The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including those with higher privileges.
nvd
CVE-2024-8175P3HIGHCVSS 7.5fixed in 4.14.0.02024-09-25
CVE-2024-8175 [HIGH] CWE-754 CVE-2024-8175: An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS.
nvd
CVE-2026-8047P3HIGHCVSS 7.5≥ 4.15.0.0, < 4.21.0.02026-05-26
CVE-2026-8047 [HIGH] CWE-1284 CVE-2026-8047: The affected products perform improper length checking when parsing incoming HTTP requests, resultin The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited out-of-bounds write. An unauthenticated remote attacker can exploit this flaw to cause a denial of service via a system crash on the affected device.
nvd
CVE-2024-5000P3HIGHCVSS 7.5fixed in 4.12.0.02024-06-04
CVE-2024-5000 [HIGH] CWE-131 CVE-2024-5000: An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to af An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS products which can cause a DoS due to incorrect calculation of buffer size.
nvd
CVE-2026-3509P3HIGHCVSS 7.5≥ 4.1.0.0, < 4.21.0.02026-03-24
CVE-2026-3509 [HIGH] CWE-134 CVE-2026-3509: An unauthenticated remote attacker may be able to control the format string of messages processed by An unauthenticated remote attacker may be able to control the format string of messages processed by the Audit Log of the CODESYS Control runtime system, potentially resulting in a denial‑of‑service (DoS) condition.
nvd
CVE-2025-41738P3HIGHCVSS 7.5≥ 4.5.0.0, < 4.19.0.02025-12-01
CVE-2025-41738 [HIGH] CWE-843 CVE-2025-41738: An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.
nvd
CVE-2025-41739P4MEDIUMCVSS 5.9≥ 4.15.0.0, < 4.19.0.02025-12-01
CVE-2025-41739 [MEDIUM] CWE-125 CVE-2025-41739: An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communicat An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.
nvd
CVE-2025-0694P4MEDIUMCVSS 6.6fixed in 4.16.0.02025-03-18
CVE-2025-0694 [MEDIUM] CWE-22 CVE-2025-0694: Insufficient path validation in CODESYS Control allows low privileged attackers with physical access Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access.
nvd
Codesys Control For Linux Arm Sl vulnerabilities | cvebase