Codesys Control Runtime System Toolkit vulnerabilities
40 known vulnerabilities affecting codesys/codesys_control_runtime_system_toolkit.
Total CVEs
40
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH20MEDIUM20
Vulnerabilities
Page 1 of 2
CVE-2022-4046HIGHCVSS 8.8vall2023-08-03
CVE-2022-4046 [HIGH] CWE-119 CVE-2022-4046: In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a
In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.
cvelistv5nvd
CVE-2023-37559MEDIUMCVSS 6.5fixed in V3.5.19.202023-08-03
CVE-2023-37559 [MEDIUM] CWE-20 CODESYS Improper Validation of Consistency within Input in multiple products
CODESYS Improper Validation of Consistency within Input in multiple products
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerab
cvelistv5
CVE-2023-37556MEDIUMCVSS 6.5fixed in V3.5.19.202023-08-03
CVE-2023-37556 [MEDIUM] CWE-20 CODESYS Improper Input Validation in CmpAppBP
CODESYS Improper Input Validation in CmpAppBP
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-3
cvelistv5
CVE-2023-37555MEDIUMCVSS 6.5fixed in V3.5.19.202023-08-03
CVE-2023-37555 [MEDIUM] CWE-20 CODESYS Improper Input Validation in CmpAppBP
CODESYS Improper Input Validation in CmpAppBP
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-3
cvelistv5
CVE-2023-37546MEDIUMCVSS 6.5fixed in V3.5.19.202023-08-03
CVE-2023-37546 [MEDIUM] CWE-20 CODESYS: Improper Input Validation in CmpApp component
CODESYS: Improper Input Validation in CmpApp component
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-3
cvelistv5
CVE-2023-37552MEDIUMCVSS 6.5fixed in V3.5.19.202023-08-03
CVE-2023-37552 [MEDIUM] CWE-20 CVE-2023-37552: In multiple versions of multiple Codesys products, after successful authentication as a user, specif
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37553, CV
cvelistv5nvd
CVE-2023-37558MEDIUMCVSS 6.5fixed in V3.5.19.202023-08-03
CVE-2023-37558 [MEDIUM] CWE-20 CVE-2023-37558: After successful authentication as a user in multiple Codesys products in multiple versions, specifi
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37559
cvelistv5nvd
CVE-2023-37551MEDIUMCVSS 6.5fixed in V3.5.19.202023-08-03
CVE-2023-37551 [MEDIUM] CWE-552 CVE-2023-37551: In multiple Codesys products in multiple versions, after successful authentication as a user, specia
In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communication requests can utilize the CmpApp component to download files with any file extensions to the controller. In contrast to the regular file download via CmpFileTransfer, no filtering of certain file types is performed her
cvelistv5nvd
CVE-2023-37548MEDIUMCVSS 6.5fixed in V3.5.19.202023-08-03
CVE-2023-37548 [MEDIUM] CWE-20 CODESYS: Improper Input Validation in CmpApp component
CODESYS: Improper Input Validation in CmpApp component
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-3
cvelistv5
CVE-2023-37545MEDIUMCVSS 6.5fixed in V3.5.19.202023-08-03
CVE-2023-37545 [MEDIUM] CWE-20 CVE-2023-37545: In multiple Codesys products in multiple versions, after successful authentication as a user, specif
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37546, CVE-
cvelistv5nvd
CVE-2023-37550MEDIUMCVSS 6.5fixed in V3.5.19.202023-08-03
CVE-2023-37550 [MEDIUM] CWE-20 CODESYS: Improper Input Validation in CmpApp component
CODESYS: Improper Input Validation in CmpApp component
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-3
cvelistv5
CVE-2023-37553MEDIUMCVSS 6.5fixed in V3.5.19.202023-08-03
CVE-2023-37553 [MEDIUM] CWE-20 CODESYS Improper Input Validation in CmpAppBP
CODESYS Improper Input Validation in CmpAppBP
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37554, CVE-2023-3
cvelistv5
CVE-2023-37557MEDIUMCVSS 6.5fixed in V3.5.19.202023-08-03
CVE-2023-37557 [MEDIUM] CWE-787 CVE-2023-37557: After successful authentication as a user in multiple Codesys products in multiple versions, specifi
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.
cvelistv5nvd
CVE-2023-37547MEDIUMCVSS 6.5fixed in V3.5.19.202023-08-03
CVE-2023-37547 [MEDIUM] CWE-20 CODESYS: Improper Input Validation in CmpApp component
CODESYS: Improper Input Validation in CmpApp component
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-3
cvelistv5
CVE-2023-37554MEDIUMCVSS 6.5fixed in V3.5.19.202023-08-03
CVE-2023-37554 [MEDIUM] CWE-20 CODESYS Improper Input Validation in CmpAppBP
CODESYS Improper Input Validation in CmpAppBP
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-3
cvelistv5
CVE-2023-37549MEDIUMCVSS 6.5fixed in V3.5.19.202023-08-03
CVE-2023-37549 [MEDIUM] CWE-20 CODESYS: Improper Input Validation in CmpApp component
CODESYS: Improper Input Validation in CmpApp component
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-3
cvelistv5
CVE-2022-47384HIGHCVSS 8.8≥ V0.0.0.0, < V3.5.19.02023-05-15
CVE-2022-47384 [HIGH] CWE-787 CVE-2022-47384: An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpT
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
cvelistv5nvd
CVE-2022-47386HIGHCVSS 8.8≥ V0.0.0.0, < V3.5.19.02023-05-15
CVE-2022-47386 [HIGH] CWE-787 CVE-2022-47386: An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the Cmp
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
cvelistv5nvd
CVE-2022-47381HIGHCVSS 8.8≥ V0.0.0.0, < V3.5.19.02023-05-15
CVE-2022-47381 [HIGH] CWE-787 CVE-2022-47381: An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
cvelistv5nvd
CVE-2022-47383HIGHCVSS 8.8≥ V0.0.0.0, < V3.5.19.02023-05-15
CVE-2022-47383 [HIGH] CWE-787 CVE-2022-47383: An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the Cmp
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
cvelistv5nvd
1 / 2Next →