Codesys Development System V3 vulnerabilities
30 known vulnerabilities affecting codesys/codesys_development_system_v3.
Total CVEs
30
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH21MEDIUM9
Vulnerabilities
Page 2 of 2
CVE-2022-47392MEDIUMCVSS 6.5≥ V0.0.0.0, < V3.5.19.02023-05-15
CVE-2022-47392 [MEDIUM] CWE-20 CVE-2022-47392: An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/Cm
An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which can lead to a denial-of-service condition.
nvd
CVE-2022-47393MEDIUMCVSS 6.5≥ V0.0.0.0, < V3.5.19.02023-05-15
CVE-2022-47393 [MEDIUM] CWE-119 CVE-2022-47393: An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of
An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple versions of multiple CODESYS products to force a denial-of-service situation.
nvd
CVE-2022-47378MEDIUMCVSS 6.5≥ V0.0.0.0, < V3.5.19.02023-05-15
CVE-2022-47378 [MEDIUM] CWE-20 CVE-2022-47378: Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerabilit
Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated remote attacker may craft specific requests that use the vulnerability leading to a denial-of-service condition.
nvd
CVE-2022-30792HIGHCVSS 7.5≥ V3, < V3.5.18.102022-07-11
CVE-2022-30792 [HIGH] CWE-400 CVE-2022-30792: In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows
In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected.
nvd
CVE-2022-30791HIGHCVSS 7.5≥ V3, < V3.5.18.102022-07-11
CVE-2022-30791 [HIGH] CWE-400 CVE-2022-30791: In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an u
In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected.
nvd
CVE-2022-22515HIGHCVSS 8.1≥ V3, < V3.5.17.402022-04-07
CVE-2022-22515 [HIGH] CWE-668 CVE-2022-22515: A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime sy
A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.
nvd
CVE-2022-22516HIGHCVSS 7.8≥ V3.5.18.0, < V3.5.18.02022-04-07
CVE-2022-22516 [HIGH] CWE-732 CVE-2022-22516: The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system use
The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space.
nvd
CVE-2022-22514HIGHCVSS 7.1≥ V3.5.18.0, < V3.5.18.02022-04-07
CVE-2022-22514 [HIGH] CWE-822 CVE-2022-22514: An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request.
An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed, this results in a crash.
nvd
CVE-2022-22517HIGHCVSS 7.5≥ V3.5.18.0, < V3.5.18.02022-04-07
CVE-2022-22517 [HIGH] CWE-334 CVE-2022-22517: An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS prod
An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.
nvd
CVE-2022-22513MEDIUMCVSS 6.5≥ V3.5.18.0, < V3.5.18.02022-04-07
CVE-2022-22513 [MEDIUM] CWE-476 CVE-2022-22513: An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component o
An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.
nvd
← Previous2 / 2