cbcvebase.

Codesys Control For Plcnext Sl vulnerabilities

44 known vulnerabilities affecting codesys/control_for_plcnext_sl.

Total CVEs
44
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH23MEDIUM21

Vulnerabilities

Page 3 of 3
CVE-2022-47392P4MEDIUMCVSS 6.5fixed in 4.8.0.02023-05-15
CVE-2022-47392 [MEDIUM] CWE-20 CVE-2022-47392: An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/Cm An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which can lead to a denial-of-service condition.
nvd
CVE-2023-37557P4MEDIUMCVSS 6.5fixed in 4.10.0.02023-08-03
CVE-2023-37557 [MEDIUM] CWE-787 CVE-2023-37557: After successful authentication as a user in multiple Codesys products in multiple versions, specifi After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.
nvd
CVE-2025-41658P4MEDIUMCVSS 5.5≥ 0.0.0.0, < 4.16.0.02025-08-04
CVE-2025-41658 [MEDIUM] CWE-276 CVE-2025-41658: CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.
nvd
CVE-2022-22508P4MEDIUMCVSS 4.3fixed in 4.7.0.02023-05-15
CVE-2022-22508 [MEDIUM] CWE-20 CVE-2022-22508: Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remo Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block consecutive logins of a specific type.
nvd
Codesys Control For Plcnext Sl vulnerabilities | cvebase