Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2022-32141

Disclosure Date: June 15, 2022 (last updated February 24, 2025)
Multiple CODESYS Products are prone to a buffer over read. A low privileged remote attacker may craft a request with an invalid offset, which can cause an internal buffer over-read, resulting in a denial-of-service condition. User interaction is not required.
0
Attacker Value
Unknown

CVE-2022-32139

Disclosure Date: June 15, 2022 (last updated February 24, 2025)
In multiple CODESYS products, a low privileged remote attacker may craft a request, which cause an out-of-bounds read, resulting in a denial-of-service condition. User Interaction is not required.
0
Attacker Value
Unknown

CVE-2021-34596

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition.
Attacker Value
Unknown

CVE-2021-34595

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.
Attacker Value
Unknown

CVE-2021-34593

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.
0
Attacker Value
Unknown

CVE-2021-30186

Disclosure Date: May 25, 2021 (last updated February 22, 2025)
CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.
Attacker Value
Unknown

CVE-2021-30195

Disclosure Date: May 25, 2021 (last updated February 22, 2025)
CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.
Attacker Value
Unknown

CVE-2019-19789

Disclosure Date: December 20, 2019 (last updated November 27, 2024)
3S-Smart CODESYS SP Realtime NT before V2.3.7.28, CODESYS Runtime Toolkit 32 bit full before V2.4.7.54, and CODESYS PLCWinNT before V2.4.7.54 allow a NULL pointer dereference.