Codesys
Codesys Edge Gateway: vulnerabilidades y CVE
Codesys Edge Gateway tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-30792 | Alta (7.5) | 0.89% | — | 11 jul 2022 | In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected. |
| CVE-2022-30791 | Alta (7.5) | 0.89% | — | 11 jul 2022 | In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected. |
| CVE-2022-31805 | Alta (7.5) | 1.0% | — | 24 jun 2022 | In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected. |
| CVE-2022-22517 | Alta (7.5) | 1.3% | — | 7 abr 2022 | An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed. |
| CVE-2022-22514 | Alta (7.1) | 0.89% | — | 7 abr 2022 | An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither… |
| CVE-2022-22513 | Media (6.5) | 1.0% | — | 7 abr 2022 | An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash. |
| CVE-2021-29242 | Alta (7.3) | 1.1% | — | 3 may 2021 | CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level… |
| CVE-2021-29241 | Alta (7.5) | 1.4% | — | 3 may 2021 | CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS). |
Otros productos de Codesys
Control FOR Pfc100 SL · 52Control FOR Linux SL · 52Control FOR Pfc200 SL · 52Control FOR Iot2000 SL · 52Control Runtime System Toolkit · 52Control FOR Raspberry PI SL · 51Control FOR Beaglebone SL · 50Control FOR Empc-a/imx6 SL · 49Development System · 44Control FOR Wago Touch Panels 600 SL · 43Control FOR Plcnext SL · 42Control RTE SL · 30