📦 Control Runtime System Toolkit

by Codesys

🔍 What is Control Runtime System Toolkit?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-33485

CRITICAL CVSS 9.8 Aug 3, 2021

CVE-2021-33485 is a critical heap-based buffer overflow vulnerability in CODESYS Control Runtime systems. Successful exploitation could allow remote attackers to execute arbitrary code or cause denial...

CVE-2022-47387

HIGH CVSS 8.8 May 15, 2023

CVE-2022-47387 is a stack-based out-of-bounds write vulnerability in the CmpTraceMgr component of CODESYS industrial automation software. Authenticated remote attackers can exploit this to cause denia...

CVE-2022-47389

HIGH CVSS 8.8 May 15, 2023

This vulnerability allows authenticated remote attackers to exploit a stack-based out-of-bounds write in the CmpTraceMgr component of CODESYS products. Successful exploitation could lead to denial-of-...

CVE-2022-47391

HIGH CVSS 7.5 May 15, 2023

CVE-2022-47391 is an improper input validation vulnerability in multiple CODESYS products that allows unauthorized remote attackers to read from invalid memory addresses, potentially causing denial of...

CVE-2022-47379

HIGH CVSS 8.8 May 15, 2023

CVE-2022-47379 is an out-of-bounds write vulnerability in multiple CODESYS industrial automation products that allows authenticated remote attackers to write arbitrary data to memory. This can lead to...

CVE-2022-47381

HIGH CVSS 8.8 May 15, 2023

This vulnerability allows authenticated remote attackers to exploit a stack-based out-of-bounds write in multiple CODESYS products, potentially leading to denial-of-service, memory corruption, or remo...

CVE-2022-47383

HIGH CVSS 8.8 May 15, 2023

An authenticated remote attacker can exploit a stack-based out-of-bounds write vulnerability in the CmpTraceMgr component of CODESYS products to cause denial-of-service, memory corruption, or potentia...

CVE-2022-47385

HIGH CVSS 8.8 May 15, 2023

An authenticated remote attacker can exploit a stack-based out-of-bounds write vulnerability in the CmpAppForce component of CODESYS products to cause denial-of-service, memory corruption, or remote c...

CVE-2022-30792

HIGH CVSS 7.5 Jul 11, 2022

CVE-2022-30792 is a denial-of-service vulnerability in CODESYS V3's CmpChannelServer component that allows unauthorized attackers to consume resources and block new communication channel connections. ...

CVE-2022-22514

HIGH CVSS 7.1 Apr 7, 2022

CVE-2022-22514 is a memory corruption vulnerability in CODESYS Control runtime systems that allows authenticated remote attackers to cause denial of service through system crashes. Attackers can deref...

CVE-2022-22519

HIGH CVSS 7.5 Apr 7, 2022

CVE-2022-22519 is a buffer over-read vulnerability in CODESYS Control runtime system webserver that allows remote, unauthenticated attackers to crash the webserver by sending crafted HTTP/HTTPS reques...

CVE-2021-36763

HIGH CVSS 7.5 Aug 3, 2021

CVE-2021-36763 is a directory traversal vulnerability in CODESYS V3 web server that allows external attackers to access files or directories they shouldn't have permission to view. This affects CODESY...

CVE-2021-29242

HIGH CVSS 7.3 May 3, 2021

CVE-2021-29242 is an improper input validation vulnerability in CODESYS Control Runtime systems that allows attackers to send crafted packets to manipulate the router's addressing scheme. This can ena...