cbcvebase.

Codesys Control For Pfc100 Sl vulnerabilities

54 known vulnerabilities affecting codesys/control_for_pfc100_sl.

Total CVEs
54
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH30MEDIUM22

Vulnerabilities

Page 3 of 3
CVE-2023-37554P4MEDIUMCVSS 6.5fixed in 4.10.0.02023-08-03
CVE-2023-37554 [MEDIUM] CVE-2023-37554: In multiple versions of multiple Codesys products, after successful authentication as a user, specif In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-
nvd
CVE-2023-37550P4MEDIUMCVSS 6.5fixed in 4.10.0.02023-08-03
CVE-2023-37550 [MEDIUM] CVE-2023-37550: In multiple Codesys products in multiple versions, after successful authentication as a user, specif In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37
nvd
CVE-2023-37548P4MEDIUMCVSS 6.5fixed in 4.10.0.02023-08-03
CVE-2023-37548 [MEDIUM] CVE-2023-37548: In multiple Codesys products in multiple versions, after successful authentication as a user, specif In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37
nvd
CVE-2023-37558P4MEDIUMCVSS 6.5fixed in 4.10.0.02023-08-03
CVE-2023-37558 [MEDIUM] CWE-20 CVE-2023-37558: After successful authentication as a user in multiple Codesys products in multiple versions, specifi After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37559
nvd
CVE-2023-37545P4MEDIUMCVSS 6.5fixed in 4.10.0.02023-08-03
CVE-2023-37545 [MEDIUM] CWE-20 CVE-2023-37545: In multiple Codesys products in multiple versions, after successful authentication as a user, specif In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37546, CVE-
nvd
CVE-2023-37546P4MEDIUMCVSS 6.5fixed in 4.10.0.02023-08-03
CVE-2023-37546 [MEDIUM] CVE-2023-37546: In multiple Codesys products in multiple versions, after successful authentication as a user, specif In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37
nvd
CVE-2023-37553P4MEDIUMCVSS 6.5fixed in 4.10.0.02023-08-03
CVE-2023-37553 [MEDIUM] CVE-2023-37553: In multiple versions of multiple Codesys products, after successful authentication as a user, specif In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-
nvd
CVE-2023-37556P4MEDIUMCVSS 6.5fixed in 4.10.0.02023-08-03
CVE-2023-37556 [MEDIUM] CVE-2023-37556: In multiple versions of multiple Codesys products, after successful authentication as a user, specif In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-
nvd
CVE-2023-37555P4MEDIUMCVSS 6.5fixed in 4.10.0.02023-08-03
CVE-2023-37555 [MEDIUM] CVE-2023-37555: In multiple versions of multiple Codesys products, after successful authentication as a user, specif In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-
nvd
CVE-2022-22513P4MEDIUMCVSS 6.5fixed in 4.5.0.02022-04-07
CVE-2022-22513 [MEDIUM] CWE-476 CVE-2022-22513: An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component o An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.
nvd
CVE-2022-47392P4MEDIUMCVSS 6.5fixed in 4.8.0.02023-05-15
CVE-2022-47392 [MEDIUM] CWE-20 CVE-2022-47392: An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/Cm An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which can lead to a denial-of-service condition.
nvd
CVE-2023-37557P4MEDIUMCVSS 6.5fixed in 4.10.0.02023-08-03
CVE-2023-37557 [MEDIUM] CWE-787 CVE-2023-37557: After successful authentication as a user in multiple Codesys products in multiple versions, specifi After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.
nvd
CVE-2025-41658P4MEDIUMCVSS 5.5≥ 0.0.0.0, < 4.16.0.02025-08-04
CVE-2025-41658 [MEDIUM] CWE-276 CVE-2025-41658: CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.
nvd
CVE-2022-22508P4MEDIUMCVSS 4.3fixed in 4.7.0.02023-05-15
CVE-2022-22508 [MEDIUM] CWE-20 CVE-2022-22508: Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remo Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block consecutive logins of a specific type.
nvd
Codesys Control For Pfc100 Sl vulnerabilities | cvebase