cbcvebase.

Codesys Development System vulnerabilities

8 known vulnerabilities affecting codesys/codesys_development_system.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7LOW1

Vulnerabilities

Page 1 of 1
CVE-2023-3663P3HIGHCVSS 8.8≥ 3.5.11.20, < 3.5.19.202023-08-03
CVE-2023-3663 [HIGH] CWE-940 CVE-2023-3663: In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to manipulate the content of notifications received via HTTP by the CODESYS notification server.
nvd
CVE-2025-41700P3HIGHCVSS 7.8≥ 0.0.0, < 3.5.21.402025-12-01
CVE-2025-41700 [HIGH] CWE-502 CVE-2025-41700: An unauthenticated attacker can trick a local user into executing arbitrary code by opening a delibe An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.
nvd
CVE-2026-44468P3HIGHCVSS 7.8≥ 3.0.0.0, < 3.5.22.202026-05-26
CVE-2026-44468 [HIGH] CWE-276 CVE-2026-44468: The affected product creates a directory with insecure default permissions during administrative ins The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary components.
nvd
CVE-2022-31805P3HIGHCVSS 7.5≥ V2, < V2.3.9.69≥ V3, < V3.5.18.302022-06-24
CVE-2022-31805 [HIGH] CWE-523 CVE-2022-31805: In the CODESYS Development System multiple components in multiple versions transmit the passwords fo In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
nvd
CVE-2023-3662P3HIGHCVSS 7.3≥ 3.5.17.0, < 3.5.19.202023-08-03
CVE-2023-3662 [HIGH] CWE-427 CVE-2023-3662: In CODESYS Development System versions from 3.5.17.0 and prior to 3.5.19.20 a vulnerability allows f In CODESYS Development System versions from 3.5.17.0 and prior to 3.5.19.20 a vulnerability allows for execution of binaries from the current working directory in the users context .
nvd
CVE-2026-44469P3HIGHCVSS 7.0≥ 3.0.0.0, < 3.5.22.202026-05-26
CVE-2026-44469 [HIGH] CWE-276 CVE-2026-44469: The affected product extracts installation files to a temporary directory with incorrect default per The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with malicious ones before installation, resulting in local privilege escalation.
nvd
CVE-2023-3670P4HIGHCVSS 7.3≥ 3.5.9.0, < 3.5.17.02023-07-28
CVE-2023-3670 [HIGH] CWE-668 CVE-2023-3670: In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe di In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.
nvd
CVE-2023-3669P4LOWCVSS 3.3≥ 3.0.0.0, < 3.5.19.202023-08-03
CVE-2023-3669 [LOW] CWE-307 CVE-2023-3669: A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local att A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimited attempts of guessing the password within an import dialog.
nvd
Codesys Development System vulnerabilities | cvebase