Home/Product/codesys safety sil
Product

codesys safety sil

37 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-37559
< 3.5.19.20
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communicatio
6.5MEDIUM
CVE-2023-37558
< 3.5.19.20
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communicatio
6.5MEDIUM
CVE-2023-37557
< 3.5.19.20
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication
6.5MEDIUM
CVE-2023-37556
< 3.5.19.20
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communicati
6.5MEDIUM
CVE-2023-37555
< 3.5.19.20
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communicati
6.5MEDIUM
CVE-2023-37554
< 3.5.19.20
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communicati
6.5MEDIUM
CVE-2023-37553
< 3.5.19.20
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communicati
6.5MEDIUM
CVE-2023-37552
< 3.5.19.20
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communicati
6.5MEDIUM
CVE-2023-37551
< 3.5.19.20
In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communicat
6.5MEDIUM
CVE-2023-37550
< 3.5.19.20
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communicati
6.5MEDIUM
CVE-2023-37549
< 3.5.19.20
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communicati
6.5MEDIUM
CVE-2023-37548
< 3.5.19.20
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communicati
6.5MEDIUM
CVE-2023-37547
< 3.5.19.20
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communicati
6.5MEDIUM
CVE-2023-37546
< 3.5.19.20
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communicati
6.5MEDIUM
CVE-2023-37545
< 3.5.19.20
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communicati
6.5MEDIUM
CVE-2022-47393
< 3.5.19.0
An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability
6.5MEDIUM
CVE-2022-47392
< 3.5.19.0
An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components
6.5MEDIUM
CVE-2022-47391
< 3.5.19.0
In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerabili
7.5HIGH
CVE-2022-47390
< 3.5.19.0
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple
8.8HIGH
CVE-2022-47389
< 3.5.19.0
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple
8.8HIGH
CVE-2022-47388
< 3.5.19.0
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple
8.8HIGH
CVE-2022-47387
< 3.5.19.0
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple
8.8HIGH
CVE-2022-47386
< 3.5.19.0
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple
8.8HIGH
CVE-2022-47385
< 3.5.19.0
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component of multiple
8.8HIGH
CVE-2022-47384
< 3.5.19.0
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple
8.8HIGH
CVE-2022-47383
< 3.5.19.0
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple
8.8HIGH
CVE-2022-47382
< 3.5.19.0
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple
8.8HIGH
CVE-2022-47381
< 3.5.19.0
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple
8.8HIGH
CVE-2022-47380
< 3.5.19.0
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multipl
8.8HIGH
CVE-2022-47379
< 3.5.19.0
An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to
8.8HIGH
CVE-2022-47378
< 3.5.19.0
Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated remote att
6.5MEDIUM
CVE-2022-4224
>= 3.0 and < 3.5.19.0
In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and
8.8HIGH
CVE-2021-29242
>= 3.0 and < 3.5.17.0
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to
7.3HIGH
CVE-2020-7052
>= 3.0 and < 3.5.15.30
CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote deni
6.5MEDIUM
CVE-2019-9009
< 3.5.15.0
An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash.
7.5HIGH
CVE-2018-20026
>= 3.0 and < 3.5.14.0
Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0.
7.5HIGH
CVE-2018-20025
>= 3.0 and < 3.5.14.0
Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin