Codesys Control For Plcnext vulnerabilities
8 known vulnerabilities affecting codesys/control_for_plcnext.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH4MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2020-12069HIGHCVSS 7.8fixed in 3.5.16.02022-12-26
CVE-2020-12069 [HIGH] CWE-916 CVE-2020-12069: In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Contro
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.
nvd
CVE-2022-30792HIGHCVSS 7.5fixed in 4.6.0.02022-07-11
CVE-2022-30792 [HIGH] CWE-400 CVE-2022-30792: In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows
In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected.
nvd
CVE-2022-30791HIGHCVSS 7.5fixed in 4.6.0.02022-07-11
CVE-2022-30791 [HIGH] CWE-400 CVE-2022-30791: In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an u
In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected.
nvd
CVE-2020-15806HIGHCVSS 7.5fixed in 3.5.16.102020-07-22
CVE-2020-15806 [HIGH] CWE-401 CVE-2020-15806: CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
nvd
CVE-2020-12068MEDIUMCVSS 6.5fixed in 3.5.16.02020-05-14
CVE-2020-12068 [MEDIUM] CVE-2020-12068: An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS R
An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.
nvd
CVE-2020-10245CRITICALCVSS 9.8fixed in 3.5.15.402020-03-26
CVE-2020-10245 [CRITICAL] CWE-787 CVE-2020-10245: CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer ove
CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.
nvd
CVE-2020-7052MEDIUMCVSS 6.5fixed in 3.5.15.302020-01-24
CVE-2020-7052 [MEDIUM] CWE-770 CVE-2020-7052: CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation whi
CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.
nvd
CVE-2019-18858CRITICALCVSS 9.8fixed in 3.5.15.202019-11-20
CVE-2019-18858 [CRITICAL] CWE-120 CVE-2019-18858: CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Bu
CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.
nvd