Vulnerabilities
Vulnerable Software
Codesys:  >> Plcwinnt  >> 2.4.7.54  Security Vulnerabilities
Multiple CODESYS products are affected to a buffer overflow.A low privileged remote attacker may craft a request, which can cause a buffer copy without checking the size of the service, resulting in a denial-of-service condition. User Interaction is not required.
CVSS Score
6.5
EPSS Score
0.003
Published
2022-06-24
In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.
CVSS Score
7.5
EPSS Score
0.008
Published
2021-10-26
A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.
CVSS Score
8.1
EPSS Score
0.005
Published
2021-10-26
A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition.
CVSS Score
6.5
EPSS Score
0.002
Published
2021-10-26
CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.
CVSS Score
7.5
EPSS Score
0.005
Published
2021-05-25
CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.
CVSS Score
7.5
EPSS Score
0.004
Published
2021-05-25


Contact Us

Shodan ® - All rights reserved