Codesys Edge Gateway For Linux vulnerabilities
7 known vulnerabilities affecting codesys/codesys_edge_gateway_for_linux.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2025-41739MEDIUMCVSS 5.9≥ 4.15.0.0, < 4.19.0.02025-12-01
CVE-2025-41739 [MEDIUM] CWE-125 CVE-2025-41739: An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communicat
An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.
cvelistv5nvd
CVE-2022-47391HIGHCVSS 7.5≥ V0.0.0.0, < V4.8.0.02023-05-15
CVE-2022-47391 [HIGH] CWE-20 CVE-2022-47391: In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a imprope
In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from invalid addresses leading to a denial of service.
cvelistv5nvd
CVE-2022-30792HIGHCVSS 7.5≥ V3, < V4.5.0.02022-07-11
CVE-2022-30792 [HIGH] CWE-400 CVE-2022-30792: In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows
In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected.
cvelistv5nvd
CVE-2022-30791HIGHCVSS 7.5≥ V3, < V4.5.0.02022-07-11
CVE-2022-30791 [HIGH] CWE-400 CVE-2022-30791: In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an u
In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected.
cvelistv5nvd
CVE-2022-22514HIGHCVSS 7.1≥ V4.5.0.0, < V4.5.0.02022-04-07
CVE-2022-22514 [HIGH] CWE-822 CVE-2022-22514: An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request.
An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed, this results in a crash.
cvelistv5nvd
CVE-2022-22517HIGHCVSS 7.5≥ V4.5.0.0, < V4.5.0.02022-04-07
CVE-2022-22517 [HIGH] CWE-334 CVE-2022-22517: An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS prod
An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.
cvelistv5nvd
CVE-2022-22513MEDIUMCVSS 6.5≥ V4.5.0.0, < V4.5.0.02022-04-07
CVE-2022-22513 [MEDIUM] CWE-476 CVE-2022-22513: An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component o
An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.
cvelistv5nvd