CVE-2025-41691
- EPSS 0.12%
- Published 04.08.2025 08:15:48
- Last modified 04.08.2025 15:06:15
An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading to a denial-of-service (DoS) condition.
CVE-2018-25048
- EPSS 0.46%
- Published 23.03.2023 11:15:12
- Last modified 21.11.2024 04:03:26
The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to access and modify all system files as well as DoS the device.
CVE-2020-12069
- EPSS 0.03%
- Published 26.12.2022 19:15:10
- Last modified 05.05.2025 14:15:00
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to...
CVE-2020-15806
- EPSS 0.59%
- Published 22.07.2020 19:15:12
- Last modified 21.11.2024 05:06:13
CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
CVE-2020-12068
- EPSS 0.24%
- Published 14.05.2020 21:15:13
- Last modified 21.11.2024 04:59:12
An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.
- EPSS 0.83%
- Published 26.03.2020 04:15:11
- Last modified 21.11.2024 04:55:03
CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.
CVE-2020-7052
- EPSS 0.76%
- Published 24.01.2020 20:15:10
- Last modified 21.11.2024 05:36:34
CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.
CVE-2019-18858
- EPSS 0.52%
- Published 20.11.2019 18:15:10
- Last modified 21.11.2024 04:33:43
CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.
CVE-2019-13542
- EPSS 0.24%
- Published 17.09.2019 19:15:10
- Last modified 21.11.2024 04:25:06
3S-Smart Software Solutions GmbH CODESYS V3 OPC UA Server, all versions 3.5.11.0 to 3.5.15.0, allows an attacker to send crafted requests from a trusted OPC UA client that cause a NULL pointer dereference, which may trigger a denial-of-service condit...
CVE-2019-9009
- EPSS 0.38%
- Published 17.09.2019 16:15:11
- Last modified 21.11.2024 04:50:48
An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash.