3s-smart Software Solutions CODESYS Development System是德国3s-smart Software Solutions公司的一套用于工业控制器和自动化技术领域的编程工具。 CODESYS Development System 多个版本的多个组件存在安全漏洞,该漏洞源于客户端和服务器之间的通信传输密码不受保护。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CODESYS | CODESYS Development System | V2 ~ V2.3.9.69 | - |
|
| CODESYS | CODESYS Gateway Client | V2 ~ V2.3.9.38 | - |
|
| CODESYS | CODESYS Gateway Server | V2 ~ V2.3.9.38 | - |
|
| CODESYS | CODESYS Web server | V1 ~ V1.1.9.23 | - |
|
| CODESYS | CODESYS SP Realtime NT | V2 ~ V2.3.7.30 | - |
|
| CODESYS | CODESYS PLCWinNT | V2 ~ V2.4.7.57 | - |
|
| CODESYS | CODESYS Runtime Toolkit 32 bit full | V2 ~ V2.4.7.57 | - |
|
| CODESYS | CODESYS Edge Gateway for Windows | V3 ~ V3.5.18.30 | - |
|
| CODESYS | CODESYS HMI (SL) | V3 ~ V3.5.18.30 | - |
|
| CODESYS | CODESYS OPC DA Server SL | V3 ~ V3.5.18.30 | - |
|
| CODESYS | CODESYS PLCHandler | V3 ~ V3.5.18.30 | - |
|
| CODESYS | CODESYS Gateway | V3 ~ V3.5.18.30 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-31802 | 9.8 CRITICAL | Partial string comparison in CODESYS gateway server |
| CVE-2022-31806 | 9.8 CRITICAL | Insecure default settings in CODESYS Runtime Toolkit 32 bit full and CODESYS PLCWinNT |
| CVE-2022-32137 | 8.8 HIGH | CODESYS Runtime System prone to heap based buffer overflow |
| CVE-2022-32138 | 8.8 HIGH | CODESYS runtime system prone to denial of service due to Unexpected Sign Extension |
| CVE-2022-32143 | 8.8 HIGH | CODESYS runtime system prone to directory acces |
| CVE-2022-1965 | 8.1 HIGH | CODESYS runtime system prone to file deletion due to improper error handling |
| CVE-2022-32142 | 8.1 HIGH | CODESYS runtime system prone to denial of service due to use of out of range pointer |
| CVE-2022-31804 | 7.5 HIGH | CODESYS Gateway server prone to denial of service attack due to excessive memory allocatio |
| CVE-2022-32136 | 6.5 MEDIUM | Codesys runtime systems: Access of uninitialised pointer lead to denial of service. |
| CVE-2022-32139 | 6.5 MEDIUM | CODESYS runtime system prone to denial of service due to out of bounds read |
| CVE-2022-32140 | 6.5 MEDIUM | CODESYS runtime system prone to denial of service due to buffer copy |
| CVE-2022-32141 | 6.5 MEDIUM | CODESYS runtime system prone to denial of service due to buffer over read |
| CVE-2022-31803 | 5.3 MEDIUM | CODESYS Gateway Server V2 prone to Denial of Service Attack |
No comments yet