Skip to main content

Vendor archive

codesys CVEs

Beta · best-effort

115 CVEs tagged to vendor codesys11 Critical, 69 High, 34 Medium, 1 Low, 0 Unrated.

CVE-2021-21869

Published Aug 25, 2021

An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A sp…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21868

Published Aug 18, 2021

An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21867

Published Aug 18, 2021

An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21863

Published Aug 5, 2021

A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially craf…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36765

Published Aug 4, 2021

In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP stack that is executed by the COD…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36764

Published Aug 4, 2021

In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-33486

Published Aug 3, 2021

All versions of the CODESYS V3 Runtime Toolkit for VxWorks from version V3.5.8.0 and before version V3.5.17.10 have Improper Handling of Exceptional Conditions.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21866

Published Aug 2, 2021

A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21865

Published Aug 2, 2021

A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Development System 3.5.16. A specially…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21864

Published Aug 2, 2021

A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29240

Published May 4, 2021

The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before installation and may be used to install CODESYS packages with ma…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29239

Published May 3, 2021

CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries without first checking their validity.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12068

Published May 14, 2020

An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.

CVSS 6.5 · Medium

CVE-2020-6081

Published May 7, 2020

An exploitable code execution vulnerability exists in the PLC_Task functionality of 3S-Smart Software Solutions GmbH CODESYS Runtime 3.5.14.30. A specially crafted network request…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-5105

Published Mar 26, 2020

An exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S-Smart Software Solutions CODESYS GatewayService. A specially crafted packet ca…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 76-100 of 115 CVEsPage 4 of 5