Codesys Control For Linux Arm Sl vulnerabilities
6 known vulnerabilities affecting codesys/control_for_linux_arm_sl.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-41738HIGHCVSS 7.5≥ 4.5.0.0, < 4.19.0.02025-12-01
CVE-2025-41738 [HIGH] CWE-843 CVE-2025-41738: An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime
An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.
nvd
CVE-2025-41659HIGHCVSS 8.3≥ 0.0.0.0, < 4.17.0.02025-08-04
CVE-2025-41659 [HIGH] CWE-732 CVE-2025-41659: A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system a
A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates as trusted. Although all services remain available, only unencrypted communication is possible if the certificates are deleted.
cvelistv5nvd
CVE-2025-41691HIGHCVSS 7.5≥ 4.16.0.0, < 4.17.0.02025-08-04
CVE-2025-41691 [HIGH] CWE-476 CVE-2025-41691: An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Co
An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading to a denial-of-service (DoS) condition.
cvelistv5nvd
CVE-2025-41658MEDIUMCVSS 5.5≥ 0.0.0.0, < 4.16.0.02025-08-04
CVE-2025-41658 [MEDIUM] CWE-276 CVE-2025-41658: CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating
CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.
cvelistv5nvd
CVE-2023-6357HIGHCVSS 8.8fixed in 4.11.0.02023-12-05
CVE-2023-6357 [HIGH] CWE-78 CVE-2023-6357: A low-privileged remote attacker could exploit the vulnerability and inject additional system comman
A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.
nvd
CVE-2021-29242HIGHCVSS 7.3≥ 3.0, < 4.1.0.02021-05-03
CVE-2021-29242 [HIGH] CWE-20 CVE-2021-29242: CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send cra
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.
nvd