šŸ“¦

control_for_pfc100_sl

Vendor: codesys

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 14 Remote Access
Total CVEs 54 Total Indexed
Avg. EPSS 1.03% Exploit Prob.
Latest CVE CVE-2025-41738 Dec 01

Security Vulnerability Index

Page 4 / 6
8.8 CVSS

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can leadĀ to a denial-of-service condition, memory overwriting, or remote code execution.

EPSS: 1.33%
8.8 CVSS

An authenticated remote attacker may use a stack basedĀ  out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can leadĀ to a denial-of-service condition, memory overwriting, or remote code execution.

EPSS: 1.33%
8.8 CVSS

An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can leadĀ to a denial-of-service condition, memory overwriting, or remote code execution.

EPSS: 1.99%
6.5 CVSS

Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated remote attacker may craft specific requests that use the vulnerability leading to a denial-of-service condition.

EPSS: 0.91%
4.3 CVSS

Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block consecutive logins of a specific type.

EPSS: 0.73%
8.8 CVSS

In multiple products of CODESYS v3 in multiple versions a remote low privileged userĀ could utilize this vulnerability to read and modify system files and OS resources or DoS the device.

EPSS: 0.88%
7.5 CVSS

In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected.

EPSS: 0.83%
7.5 CVSS

In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected.

EPSS: 0.83%
7.5 CVSS

A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system.

EPSS: 1.40%
6.5 CVSS

A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymous access to components part of the applied security policy.

EPSS: 0.59%