cbcvebase.

Codesys Runtime Toolkit vulnerabilities

25 known vulnerabilities affecting codesys/runtime_toolkit.

Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH16MEDIUM8

Vulnerabilities

Page 2 of 2
CVE-2022-32139P4MEDIUMCVSS 6.5≥ 2.0, < 2.4.7.57≥ V2, < V2.4.7.572022-06-24
CVE-2022-32139 [MEDIUM] CWE-125 CVE-2022-32139: In multiple CODESYS products, a low privileged remote attacker may craft a request, which cause an o In multiple CODESYS products, a low privileged remote attacker may craft a request, which cause an out-of-bounds read, resulting in a denial-of-service condition. User Interaction is not required.
nvd
CVE-2022-32136P4MEDIUMCVSS 6.5≥ 2.0, < 2.4.7.57≥ V2, < V2.4.7.572022-06-24
CVE-2022-32136 [MEDIUM] CWE-824 CVE-2022-32136: In multiple CODESYS products, a low privileged remote attacker may craft a request that cause a read In multiple CODESYS products, a low privileged remote attacker may craft a request that cause a read access to an uninitialized pointer, resulting in a denial-of-service. User interaction is not required.
nvd
CVE-2019-19789P4MEDIUMCVSS 6.5fixed in 2.4.7.542019-12-20
CVE-2019-19789 [MEDIUM] CWE-476 CVE-2019-19789: 3S-Smart CODESYS SP Realtime NT before V2.3.7.28, CODESYS Runtime Toolkit 32 bit full before V2.4.7. 3S-Smart CODESYS SP Realtime NT before V2.3.7.28, CODESYS Runtime Toolkit 32 bit full before V2.4.7.54, and CODESYS PLCWinNT before V2.4.7.54 allow a NULL pointer dereference.
nvd
CVE-2021-30187P4MEDIUMCVSS 5.3fixed in 2.4.7.552021-05-25
CVE-2021-30187 [MEDIUM] CWE-78 CVE-2021-30187: CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.
nvd
CVE-2025-41658P4MEDIUMCVSS 5.5≥ 0.0.0.0, < 3.5.21.202025-08-04
CVE-2025-41658 [MEDIUM] CWE-276 CVE-2025-41658: CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.
nvd
Codesys Runtime Toolkit vulnerabilities | cvebase