« Volver al listado

Codesys

Codesys Control: vulnerabilidades y CVE

Codesys Control tiene 6 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses2
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-35226Alta (7.1)0.28%—29 jul 2026
An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the…
CVE-2026-3509Alta (7.5)0.57%—24 mar 2026
An unauthenticated remote attacker may be able to control the format string of messages processed by the Audit Log of the CODESYS Control runtime system, potentially resulting in a denial‑of‑service (DoS) condition.
CVE-2025-41659Alta (8.3)0.22%—4 ago 2025
A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates…
CVE-2025-0694Media (6.6)0.27%—18 mar 2025
Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access.
CVE-2021-36763Alta (7.5)1.0%—3 ago 2021
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.
CVE-2021-33485Crítica (9.8)1.1%—3 ago 2021
CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services1
  2. T1499.004 Application or System Exploitation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Codesys