cbcvebase.

Codesys Hmi vulnerabilities

50 known vulnerabilities affecting codesys/hmi.

Total CVEs
50
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH25MEDIUM21

Vulnerabilities

Page 3 of 3
CVE-2023-37553P4MEDIUMCVSS 6.5fixed in 3.5.19.202023-08-03
CVE-2023-37553 [MEDIUM] CVE-2023-37553: In multiple versions of multiple Codesys products, after successful authentication as a user, specif In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-
nvd
CVE-2023-37556P4MEDIUMCVSS 6.5fixed in 3.5.19.202023-08-03
CVE-2023-37556 [MEDIUM] CVE-2023-37556: In multiple versions of multiple Codesys products, after successful authentication as a user, specif In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-
nvd
CVE-2023-37555P4MEDIUMCVSS 6.5fixed in 3.5.19.202023-08-03
CVE-2023-37555 [MEDIUM] CVE-2023-37555: In multiple versions of multiple Codesys products, after successful authentication as a user, specif In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-
nvd
CVE-2020-7052P4MEDIUMCVSS 6.5≥ 3.5.10.0, < 3.5.15.302020-01-24
CVE-2020-7052 [MEDIUM] CWE-770 CVE-2020-7052: CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation whi CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.
nvd
CVE-2022-47393P4MEDIUMCVSS 6.5fixed in 3.5.19.02023-05-15
CVE-2022-47393 [MEDIUM] CWE-119 CVE-2022-47393: An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple versions of multiple CODESYS products to force a denial-of-service situation.
nvd
CVE-2020-12068P4MEDIUMCVSS 6.5≥ 3.0, < 3.5.16.02020-05-14
CVE-2020-12068 [MEDIUM] CVE-2020-12068: An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS R An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.
nvd
CVE-2022-47378P4MEDIUMCVSS 6.5fixed in 3.5.19.02023-05-15
CVE-2022-47378 [MEDIUM] CWE-20 CVE-2022-47378: Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerabilit Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated remote attacker may craft specific requests that use the vulnerability leading to a denial-of-service condition.
nvd
CVE-2022-47392P4MEDIUMCVSS 6.5fixed in 3.5.19.02023-05-15
CVE-2022-47392 [MEDIUM] CWE-20 CVE-2022-47392: An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/Cm An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which can lead to a denial-of-service condition.
nvd
CVE-2023-37557P4MEDIUMCVSS 6.5fixed in 3.5.19.202023-08-03
CVE-2023-37557 [MEDIUM] CWE-787 CVE-2023-37557: After successful authentication as a user in multiple Codesys products in multiple versions, specifi After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.
nvd
CVE-2022-22508P4MEDIUMCVSS 4.3fixed in 3.5.18.402023-05-15
CVE-2022-22508 [MEDIUM] CWE-20 CVE-2022-22508: Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remo Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block consecutive logins of a specific type.
nvd
Codesys Hmi vulnerabilities | cvebase