Codesys Control For Pfc200 Sl vulnerabilities

48 known vulnerabilities affecting codesys/codesys_control_for_pfc200_sl.

Total CVEs
48
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH26MEDIUM22

Vulnerabilities

Page 1 of 3
CVE-2025-41660HIGHCVSS 8.8≥ 0.0.0, < 4.21.0.02026-03-24
CVE-2025-41660 [HIGH] CWE-669 CVE-2025-41660: A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.
cvelistv5nvd
CVE-2026-3509HIGHCVSS 7.5≥ 4.1.0.0, < 4.21.0.02026-03-24
CVE-2026-3509 [HIGH] CWE-134 CVE-2026-3509: An unauthenticated remote attacker may be able to control the format string of messages processed by An unauthenticated remote attacker may be able to control the format string of messages processed by the Audit Log of the CODESYS Control runtime system, potentially resulting in a denial‑of‑service (DoS) condition.
cvelistv5nvd
CVE-2025-41738HIGHCVSS 7.5≥ 4.5.0.0, < 4.19.0.02025-12-01
CVE-2025-41738 [HIGH] CWE-843 CVE-2025-41738: An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.
cvelistv5nvd
CVE-2025-41739MEDIUMCVSS 5.9≥ 4.15.0.0, < 4.19.0.02025-12-01
CVE-2025-41739 [MEDIUM] CWE-125 CVE-2025-41739: An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communicat An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.
cvelistv5nvd
CVE-2025-0694MEDIUMCVSS 6.6fixed in 4.16.0.02025-03-18
CVE-2025-0694 [MEDIUM] CWE-22 CVE-2025-0694: Insufficient path validation in CODESYS Control allows low privileged attackers with physical access Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access.
cvelistv5nvd
CVE-2024-8175HIGHCVSS 7.5fixed in 4.14.0.02024-09-25
CVE-2024-8175 [HIGH] CWE-754 CVE-2024-8175: An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS.
cvelistv5nvd
CVE-2024-5000HIGHCVSS 7.5fixed in 4.12.0.02024-06-04
CVE-2024-5000 [HIGH] CWE-131 CVE-2024-5000: An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to af An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS products which can cause a DoS due to incorrect calculation of buffer size.
cvelistv5nvd
CVE-2023-6357HIGHCVSS 8.8fixed in 4.11.0.02023-12-05
CVE-2023-6357 [HIGH] CWE-78 CVE-2023-6357: A low-privileged remote attacker could exploit the vulnerability and inject additional system comman A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.
cvelistv5nvd
CVE-2022-4046HIGHCVSS 8.8vall2023-08-03
CVE-2022-4046 [HIGH] CWE-119 CVE-2022-4046: In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.
cvelistv5nvd
CVE-2023-37559MEDIUMCVSS 6.5fixed in V4.10.0.02023-08-03
CVE-2023-37559 [MEDIUM] CWE-20 CODESYS Improper Validation of Consistency within Input in multiple products CODESYS Improper Validation of Consistency within Input in multiple products After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerab
cvelistv5
CVE-2023-37556MEDIUMCVSS 6.5fixed in V4.10.0.02023-08-03
CVE-2023-37556 [MEDIUM] CWE-20 CODESYS Improper Input Validation in CmpAppBP CODESYS Improper Input Validation in CmpAppBP In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-3
cvelistv5
CVE-2023-37555MEDIUMCVSS 6.5fixed in V4.10.0.02023-08-03
CVE-2023-37555 [MEDIUM] CWE-20 CODESYS Improper Input Validation in CmpAppBP CODESYS Improper Input Validation in CmpAppBP In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-3
cvelistv5
CVE-2023-37546MEDIUMCVSS 6.5fixed in V4.10.0.02023-08-03
CVE-2023-37546 [MEDIUM] CWE-20 CODESYS: Improper Input Validation in CmpApp component CODESYS: Improper Input Validation in CmpApp component In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-3
cvelistv5
CVE-2023-37552MEDIUMCVSS 6.5fixed in V4.10.0.02023-08-03
CVE-2023-37552 [MEDIUM] CWE-20 CVE-2023-37552: In multiple versions of multiple Codesys products, after successful authentication as a user, specif In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37553, CV
cvelistv5nvd
CVE-2023-37558MEDIUMCVSS 6.5fixed in V4.10.0.02023-08-03
CVE-2023-37558 [MEDIUM] CWE-20 CVE-2023-37558: After successful authentication as a user in multiple Codesys products in multiple versions, specifi After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37559
cvelistv5nvd
CVE-2023-37551MEDIUMCVSS 6.5fixed in V4.10.0.02023-08-03
CVE-2023-37551 [MEDIUM] CWE-552 CVE-2023-37551: In multiple Codesys products in multiple versions, after successful authentication as a user, specia In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communication requests can utilize the CmpApp component to download files with any file extensions to the controller. In contrast to the regular file download via CmpFileTransfer, no filtering of certain file types is performed her
cvelistv5nvd
CVE-2023-37548MEDIUMCVSS 6.5fixed in V4.10.0.02023-08-03
CVE-2023-37548 [MEDIUM] CWE-20 CODESYS: Improper Input Validation in CmpApp component CODESYS: Improper Input Validation in CmpApp component In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-3
cvelistv5
CVE-2023-37545MEDIUMCVSS 6.5fixed in V4.10.0.02023-08-03
CVE-2023-37545 [MEDIUM] CWE-20 CVE-2023-37545: In multiple Codesys products in multiple versions, after successful authentication as a user, specif In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37546, CVE-
cvelistv5nvd
CVE-2023-37550MEDIUMCVSS 6.5fixed in V4.10.0.02023-08-03
CVE-2023-37550 [MEDIUM] CWE-20 CODESYS: Improper Input Validation in CmpApp component CODESYS: Improper Input Validation in CmpApp component In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-3
cvelistv5
CVE-2023-37553MEDIUMCVSS 6.5fixed in V4.10.0.02023-08-03
CVE-2023-37553 [MEDIUM] CWE-20 CODESYS Improper Input Validation in CmpAppBP CODESYS Improper Input Validation in CmpAppBP In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37554, CVE-2023-3
cvelistv5