Skip to main content

Vendor/product archive

codesys / plcwinnt CVEs

Beta · best-effort

12 CVEs tagged to codesys / plcwinnt1 Critical, 6 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2022-32143

Published Jun 24, 2022

In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the PLC. All requests are processed…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32142

Published Jun 24, 2022

Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset, which can cause an out-of-bo…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32140

Published Jun 24, 2022

Multiple CODESYS products are affected to a buffer overflow.A low privileged remote attacker may craft a request, which can cause a buffer copy without checking the size of the se…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32139

Published Jun 24, 2022

In multiple CODESYS products, a low privileged remote attacker may craft a request, which cause an out-of-bounds read, resulting in a denial-of-service condition. User Interaction…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32137

Published Jun 24, 2022

In multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause a heap-based buffer overflow, resulting in a denial-of-service condition or mem…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32136

Published Jun 24, 2022

In multiple CODESYS products, a low privileged remote attacker may craft a request that cause a read access to an uninitialized pointer, resulting in a denial-of-service. User int…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31806

Published Jun 24, 2022

In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2022-1965

Published Jun 24, 2022

Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In co…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1