cbcvebase.

Codesys Hmi vulnerabilities

50 known vulnerabilities affecting codesys/hmi.

Total CVEs
50
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH25MEDIUM21

Vulnerabilities

Page 1 of 3
CVE-2019-13548P3CRITICALCVSS 9.8≥ 3.5.10.0, < 3.5.12.80≥ 3.5.13.0, < 3.5.14.102019-09-13
CVE-2019-13548 [CRITICAL] CWE-121 CVE-2019-13548: CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution.
nvd
CVE-2022-47379P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47379 [HIGH] CWE-787 CVE-2022-47379: An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS pr An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47386P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47386 [HIGH] CWE-787 CVE-2022-47386: An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the Cmp An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47385P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47385 [HIGH] CWE-787 CVE-2022-47385: An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the Cmp An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47384P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47384 [HIGH] CWE-787 CVE-2022-47384: An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpT An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47381P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47381 [HIGH] CWE-787 CVE-2022-47381: An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47382P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47382 [HIGH] CWE-787 CVE-2022-47382: An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpT An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47383P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47383 [HIGH] CWE-787 CVE-2022-47383: An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the Cmp An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47388P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47388 [HIGH] CWE-787 CVE-2022-47388: An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the Cmp An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47387P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47387 [HIGH] CWE-787 CVE-2022-47387: An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpT An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47380P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47380 [HIGH] CWE-787 CVE-2022-47380: An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multipl An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47390P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47390 [HIGH] CWE-787 CVE-2022-47390: An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the Cmp An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2022-47389P3HIGHCVSS 8.8fixed in 3.5.19.02023-05-15
CVE-2022-47389 [HIGH] CWE-787 CVE-2022-47389: An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the Cmp An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
nvd
CVE-2020-10245P3CRITICALCVSS 9.8≥ 3.5.10.0, < 3.5.15.402020-03-26
CVE-2020-10245 [CRITICAL] CWE-787 CVE-2020-10245: CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer ove CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.
nvd
CVE-2019-18858P3CRITICALCVSS 9.8fixed in 3.5.15.202019-11-20
CVE-2019-18858 [CRITICAL] CWE-120 CVE-2019-18858: CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Bu CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.
nvd
CVE-2021-33485P3CRITICALCVSS 9.8fixed in 3.5.17.102021-08-03
CVE-2021-33485 [CRITICAL] CWE-787 CVE-2021-33485: CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow. CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
nvd
CVE-2018-25048P3HIGHCVSS 8.8≥ 3.0, < 3.5.12.302023-03-23
CVE-2018-25048 [HIGH] CWE-22 CVE-2018-25048: The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a pa The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to access and modify all system files as well as DoS the device.
nvd
CVE-2022-4224P3HIGHCVSS 8.8≥ 3.0.0.0, < 3.5.19.02023-03-23
CVE-2022-4224 [HIGH] CWE-1188 CVE-2022-4224: In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize t In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.
nvd
CVE-2019-13532P3HIGHCVSS 7.5≥ 3.5.10.0, < 3.5.12.80≥ 3.5.13.0, < 3.5.14.102019-09-13
CVE-2019-13532 [HIGH] CWE-22 CVE-2019-13532: CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.
nvd
CVE-2019-9008P3HIGHCVSS 8.8fixed in 3.5.13.02019-09-17
CVE-2019-9008 [HIGH] CWE-732 CVE-2019-9008: An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can tak An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over the runtime.
nvd
Codesys Hmi vulnerabilities | cvebase