CVE-2018-5440
- EPSS 1.31%
- Veröffentlicht 15.02.2018 10:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:48
A Stack-based Buffer Overflow issue was discovered in 3S-Smart CODESYS Web Server. Specifically: all Microsoft Windows (also WinCE) based CODESYS web servers running stand-alone Version 2.3, or as part of the CODESYS runtime system running prior to V...
- EPSS 0.31%
- Veröffentlicht 18.10.2015 19:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Runtime Toolkit before 2.4.7.48 in 3S-Smart CODESYS before 2.3.9.48 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted request.
CVE-2014-0760
- EPSS 2.01%
- Veröffentlicht 25.04.2014 05:12:07
- Zuletzt bearbeitet 02.07.2025 21:15:39
The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion provide an undocumented access method involving the FTP protocol, which could allow a remote attacker to execute arbitrary code ...
CVE-2014-0769
- EPSS 0.33%
- Veröffentlicht 25.04.2014 05:12:07
- Zuletzt bearbeitet 02.07.2025 21:15:39
The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion do not require authentication for connections to certain TCP ports, which allows remote attackers to (1) modify the configuration ...
- EPSS 4.38%
- Veröffentlicht 21.01.2013 21:55:01
- Zuletzt bearbeitet 02.07.2025 20:15:28
The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP list...
- EPSS 2.23%
- Veröffentlicht 21.01.2013 21:55:01
- Zuletzt bearbeitet 02.07.2025 21:15:39
The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker to access files and directories outside the intended scope. This may allow an attacker to upload and download any file on the dev...