CVE-2024-41975
- EPSS 0.06%
- Veröffentlicht 18.03.2025 11:15:39
- Zuletzt bearbeitet 18.03.2025 11:15:39
An unauthenticated remote attacker can gain limited information of the PLC network but the user management of the PLCs prevents the actual access to the PLCs.
CVE-2023-5751
- EPSS 0.07%
- Veröffentlicht 04.06.2024 09:15:09
- Zuletzt bearbeitet 21.11.2024 08:42:24
A local attacker with low privileges can read and modify any users files and cause a DoS in the working directory of the affected products due to exposure of resource to wrong sphere.
- EPSS 0.39%
- Veröffentlicht 11.07.2022 11:15:08
- Zuletzt bearbeitet 21.11.2024 07:03:23
In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected.
- EPSS 0.54%
- Veröffentlicht 11.07.2022 11:15:08
- Zuletzt bearbeitet 21.11.2024 07:03:23
In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected.
CVE-2022-31805
- EPSS 0.44%
- Veröffentlicht 24.06.2022 08:15:07
- Zuletzt bearbeitet 21.11.2024 07:05:22
In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
CVE-2022-22513
- EPSS 0.55%
- Veröffentlicht 07.04.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:46:55
An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.
CVE-2022-22514
- EPSS 0.68%
- Veröffentlicht 07.04.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:46:56
An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally...
CVE-2022-22517
- EPSS 1.03%
- Veröffentlicht 07.04.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:46:56
An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.
CVE-2021-29241
- EPSS 0.56%
- Veröffentlicht 03.05.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:00:51
CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).
CVE-2021-29242
- EPSS 0.44%
- Veröffentlicht 03.05.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:00:52
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.