Codesys
Codesys Development System: vulnerabilidades y CVE
Codesys Development System tiene 44 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE44
Últimos 12 meses3
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-44469 | Alta (8.5) | 0.12% | — | 26 may 2026 | The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a… |
| CVE-2026-44468 | Alta (8.5) | 0.14% | — | 26 may 2026 | The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be… |
| CVE-2026-2364 | Alta (7.3) | 0.08% | — | 10 mar 2026 | If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS Development System, a low privileged local attacker can gain elevated rights due to a TOCTOU vulnerability in the CODESYS… |
| CVE-2023-3669 | Baja (3.3) | 0.15% | — | 3 ago 2023 | A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimited attempts of guessing the password within an import dialog. |
| CVE-2023-37559 | Media (6.5) | 0.63% | — | 3 ago 2023 | After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read… |
| CVE-2023-37558 | Media (6.5) | 0.63% | — | 3 ago 2023 | After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read… |
| CVE-2023-37557 | Media (6.5) | 0.63% | — | 3 ago 2023 | After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can… |
| CVE-2023-37556 | Media (6.5) | 0.63% | — | 3 ago 2023 | In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally… |
| CVE-2023-37555 | Media (6.5) | 0.63% | — | 3 ago 2023 | In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally… |
| CVE-2023-37554 | Media (6.5) | 0.63% | — | 3 ago 2023 | In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally… |
| CVE-2023-37553 | Media (6.5) | 0.63% | — | 3 ago 2023 | In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally… |
| CVE-2023-37552 | Media (6.5) | 0.63% | — | 3 ago 2023 | In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally… |
| CVE-2023-37551 | Media (6.5) | 0.50% | — | 3 ago 2023 | In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communication requests can utilize the CmpApp component to download files with any file extensions… |
| CVE-2023-37550 | Media (6.5) | 0.63% | — | 3 ago 2023 | In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally… |
| CVE-2023-37549 | Media (6.5) | 0.63% | — | 3 ago 2023 | In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally… |
| CVE-2023-37548 | Media (6.5) | 0.63% | — | 3 ago 2023 | In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally… |
| CVE-2023-37547 | Media (6.5) | 0.63% | — | 3 ago 2023 | In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally… |
| CVE-2023-37546 | Media (6.5) | 0.63% | — | 3 ago 2023 | In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally… |
| CVE-2023-3663 | Alta (8.8) | 1.0% | — | 3 ago 2023 | In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to manipulate the content of notifications received via HTTP by the… |
| CVE-2023-3662 | Alta (7.3) | 0.21% | — | 3 ago 2023 | In CODESYS Development System versions from 3.5.17.0 and prior to 3.5.19.20 a vulnerability allows for execution of binaries from the current working directory in the users context . |
| CVE-2023-37545 | Media (6.5) | 0.63% | — | 3 ago 2023 | In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally… |
| CVE-2023-3670 | Alta (7.3) | 0.20% | — | 28 jul 2023 | In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and… |
| CVE-2022-4224 | Alta (8.8) | 0.88% | — | 23 mar 2023 | In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device. |
| CVE-2022-30792 | Alta (7.5) | 0.89% | — | 11 jul 2022 | In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected. |
| CVE-2022-30791 | Alta (7.5) | 0.89% | — | 11 jul 2022 | In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected. |
| CVE-2022-31805 | Alta (7.5) | 1.0% | — | 24 jun 2022 | In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected. |
| CVE-2022-22519 | Alta (7.5) | 1.5% | — | 7 abr 2022 | A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system. |
| CVE-2022-22517 | Alta (7.5) | 1.3% | — | 7 abr 2022 | An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed. |
| CVE-2022-22516 | Alta (7.8) | 0.26% | — | 7 abr 2022 | The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space. |
| CVE-2022-22515 | Alta (8.1) | 1.1% | — | 7 abr 2022 | A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products. |
Otros productos de Codesys
Control FOR Iot2000 SL · 52Control FOR Linux SL · 52Control FOR Pfc200 SL · 52Control FOR Pfc100 SL · 52Control Runtime System Toolkit · 52Control FOR Raspberry PI SL · 51Control FOR Beaglebone SL · 50Control FOR Empc-a/imx6 SL · 49Control FOR Wago Touch Panels 600 SL · 43Control FOR Plcnext SL · 42Control RTE SL · 30Control WIN SL · 30