CVE-2025-41738
- EPSS 0.12%
- Veröffentlicht 01.12.2025 10:02:33
- Zuletzt bearbeitet 23.02.2026 15:42:30
An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.
CVE-2025-0694
- EPSS 0.1%
- Veröffentlicht 18.03.2025 11:15:39
- Zuletzt bearbeitet 18.03.2025 11:15:39
Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access.
CVE-2024-8175
- EPSS 0.89%
- Veröffentlicht 25.09.2024 08:15:04
- Zuletzt bearbeitet 26.09.2024 13:32:02
An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS.
CVE-2023-5751
- EPSS 0.1%
- Veröffentlicht 04.06.2024 09:15:09
- Zuletzt bearbeitet 21.11.2024 08:42:24
A local attacker with low privileges can read and modify any users files and cause a DoS in the working directory of the affected products due to exposure of resource to wrong sphere.
CVE-2022-4046
- EPSS 0.76%
- Veröffentlicht 03.08.2023 13:15:09
- Zuletzt bearbeitet 21.11.2024 07:34:30
In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.
CVE-2023-37549
- EPSS 0.08%
- Veröffentlicht 03.08.2023 12:15:10
- Zuletzt bearbeitet 21.11.2024 08:11:55
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potenti...
CVE-2023-37550
- EPSS 0.08%
- Veröffentlicht 03.08.2023 12:15:10
- Zuletzt bearbeitet 21.11.2024 08:11:55
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potenti...
CVE-2023-37551
- EPSS 0.08%
- Veröffentlicht 03.08.2023 12:15:10
- Zuletzt bearbeitet 21.11.2024 08:11:55
In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communication requests can utilize the CmpApp component to download files with any file extensions to the controller. In contrast ...
CVE-2023-37552
- EPSS 0.08%
- Veröffentlicht 03.08.2023 12:15:10
- Zuletzt bearbeitet 21.11.2024 08:11:55
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, poten...
CVE-2023-37553
- EPSS 0.08%
- Veröffentlicht 03.08.2023 12:15:10
- Zuletzt bearbeitet 21.11.2024 08:11:55
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, poten...