Codesys Control Runtime System Toolkit vulnerabilities
51 known vulnerabilities affecting codesys/control_runtime_system_toolkit.
Total CVEs
51
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH24MEDIUM23
Vulnerabilities
Page 1 of 3
CVE-2019-13548P3CRITICALCVSS 9.8≥ 3.0, < 3.5.12.802019-09-13
CVE-2019-13548 [CRITICAL] CWE-121 CVE-2019-13548: CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution.
nvd
CVE-2022-47379P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47379 [HIGH] CWE-787 CVE-2022-47379: An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS pr
An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47386P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47386 [HIGH] CWE-787 CVE-2022-47386: An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the Cmp
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47385P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47385 [HIGH] CWE-787 CVE-2022-47385: An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the Cmp
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47384P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47384 [HIGH] CWE-787 CVE-2022-47384: An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpT
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47381P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47381 [HIGH] CWE-787 CVE-2022-47381: An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47382P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47382 [HIGH] CWE-787 CVE-2022-47382: An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpT
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47383P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47383 [HIGH] CWE-787 CVE-2022-47383: An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the Cmp
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47388P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47388 [HIGH] CWE-787 CVE-2022-47388: An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the Cmp
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47387P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47387 [HIGH] CWE-787 CVE-2022-47387: An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpT
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47380P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47380 [HIGH] CWE-787 CVE-2022-47380: An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multipl
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47390P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47390 [HIGH] CWE-787 CVE-2022-47390: An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the Cmp
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47389P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47389 [HIGH] CWE-787 CVE-2022-47389: An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the Cmp
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2020-10245P3CRITICALCVSS 9.8≥ 3.0, < 3.5.15.402020-03-26
CVE-2020-10245 [CRITICAL] CWE-787 CVE-2020-10245: CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer ove
CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.
nvd
CVE-2019-18858P3CRITICALCVSS 9.8fixed in 3.5.15.202019-11-20
CVE-2019-18858 [CRITICAL] CWE-120 CVE-2019-18858: CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Bu
CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.
nvd
CVE-2021-33485P3CRITICALCVSS 9.8fixed in 3.5.17.102021-08-03
CVE-2021-33485 [CRITICAL] CWE-787 CVE-2021-33485: CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
nvd
CVE-2019-13532P3HIGHCVSS 7.5≥ 3.0, < 3.5.12.802019-09-13
CVE-2019-13532 [HIGH] CWE-22 CVE-2019-13532: CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.
nvd
CVE-2022-22515P3HIGHCVSS 8.1fixed in 3.5.18.02022-04-07
CVE-2022-22515 [HIGH] CWE-668 CVE-2022-22515: A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime sy
A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.
nvd
CVE-2022-22519P3HIGHCVSS 7.5fixed in 3.5.18.02022-04-07
CVE-2022-22519 [HIGH] CWE-126 CVE-2022-22519: A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buff
A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system.
nvd
CVE-2022-47391P3HIGHCVSS 7.5fixed in 3.5.19.02023-05-15
CVE-2022-47391 [HIGH] CWE-20 CVE-2022-47391: In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a imprope
In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from invalid addresses leading to a denial of service.
nvd
1 / 3Next →