Skip to main content

Vendor/product archive

codesys / gateway CVEs

Beta · best-effort

18 CVEs tagged to codesys / gateway2 Critical, 13 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2022-31804

Published Jun 24, 2022

The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated attacker may allocate an arbitrary amount of memory, which…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-31803

Published Jun 24, 2022

In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all available TCP connections and preve…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-31802

Published Jun 24, 2022

In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perfo…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-36764

Published Aug 4, 2021

In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9012

Published Aug 15, 2019

An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication request may cause uncontrolled memory allocations in the affected CODESYS products and may result…

CVSS 7.5 · High

CVE-2019-9010

Published Aug 15, 2019

An issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of a communication channel. All variants of the following CODE…

CVSS 9.8 · Critical
Showing 1-18 of 18 CVEsPage 1 of 1