Show filters
649 Total Results
Displaying 131-140 of 649
Sort by:
Attacker Value
Unknown

CVE-2022-32142

Disclosure Date: June 15, 2022 (last updated February 24, 2025)
Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset, which can cause an out-of-bounds read or write access, resulting in denial-of-service condition or local memory overwrite, which can lead to a change of local files. User interaction is not required.
0
Attacker Value
Unknown

CVE-2022-32141

Disclosure Date: June 15, 2022 (last updated February 24, 2025)
Multiple CODESYS Products are prone to a buffer over read. A low privileged remote attacker may craft a request with an invalid offset, which can cause an internal buffer over-read, resulting in a denial-of-service condition. User interaction is not required.
0
Attacker Value
Unknown

CVE-2022-32139

Disclosure Date: June 15, 2022 (last updated February 24, 2025)
In multiple CODESYS products, a low privileged remote attacker may craft a request, which cause an out-of-bounds read, resulting in a denial-of-service condition. User Interaction is not required.
0
Attacker Value
Unknown

CVE-2022-22515

Disclosure Date: June 01, 2022 (last updated February 23, 2025)
A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.
0
Attacker Value
Unknown

CVE-2021-3597

Disclosure Date: May 24, 2022 (last updated February 23, 2025)
A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior to 2.0.39.Final.
Attacker Value
Unknown

CVE-2022-24287

Disclosure Date: May 20, 2022 (last updated February 23, 2025)
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC06), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1 UC01), SIMATIC WinCC Runtime Professional V16 and earlier (All versions), SIMATIC WinCC Runtime Professional V17 (All versions < V17 Upd4), SIMATIC WinCC V7.3 (All versions), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 21), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 8). A missing printer configuration on the host could allow an authenticated attacker to escape the WinCC Kiosk Mode.
0
Attacker Value
Unknown

CVE-2021-22275

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Buffer Overflow vulnerability in B&R Automation Runtime webserver allows an unauthenticated network-based attacker to stop the cyclic program on the device and cause a denial of service.
Attacker Value
Unknown

CVE-2022-22518

Disclosure Date: April 06, 2022 (last updated February 23, 2025)
A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymous access to components part of the applied security policy.
0
Attacker Value
Unknown

CVE-2022-22519

Disclosure Date: April 06, 2022 (last updated February 23, 2025)
A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system.
Attacker Value
Unknown

CVE-2022-22517

Disclosure Date: April 06, 2022 (last updated February 23, 2025)
An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.