Codesys Simulation Runtime vulnerabilities

6 known vulnerabilities affecting codesys/simulation_runtime.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2018-25048HIGHCVSS 8.8≥ 3.0.0.0, < 3.5.12.302023-03-23
CVE-2018-25048 [HIGH] CWE-22 CVE-2018-25048: The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a pa The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to access and modify all system files as well as DoS the device.
nvd
CVE-2021-29242HIGHCVSS 7.3≥ 3.0, < 3.5.17.02021-05-03
CVE-2021-29242 [HIGH] CWE-20 CVE-2021-29242: CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send cra CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.
nvd
CVE-2020-15806HIGHCVSS 7.5≥ 3.5.9.40, < 3.5.16.102020-07-22
CVE-2020-15806 [HIGH] CWE-401 CVE-2020-15806: CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation. CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
nvd
CVE-2020-7052MEDIUMCVSS 6.5≥ 3.5.9.40, < 3.5.15.302020-01-24
CVE-2020-7052 [MEDIUM] CWE-770 CVE-2020-7052: CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation whi CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.
nvd
CVE-2019-9009HIGHCVSS 7.5fixed in 3.5.15.02019-09-17
CVE-2019-9009 [HIGH] CWE-755 CVE-2019-9009: An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Cont An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash.
nvd
CVE-2019-9008HIGHCVSS 8.8fixed in 3.5.13.02019-09-17
CVE-2019-9008 [HIGH] CWE-732 CVE-2019-9008: An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can tak An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over the runtime.
nvd