Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
codesys codesys 3.5.17.0 vulnerabilities and exploits
(subscribe to this query)
7.8
CVSSv3
CVE-2021-21867
An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicio...
Codesys Codesys 3.5.17.0
Codesys Codesys 3.5.16.0
7.8
CVSSv3
CVE-2021-21868
An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious ...
Codesys Codesys 3.5.17.0
Codesys Codesys 3.5.16.0
7.8
CVSSv3
CVE-2021-21869
An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious fil...
Codesys Codesys 3.5.17.0
Codesys Codesys 3.5.16.0
7.8
CVSSv3
CVE-2021-21864
A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a mali...
Codesys Development System 3.5.16.0
Codesys Development System 3.5.17.0
7.8
CVSSv3
CVE-2021-21866
A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicio...
Codesys Development System 3.5.16.0
Codesys Development System 3.5.17.0
7.8
CVSSv3
CVE-2021-21865
A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Development System 3.5.16. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to tr...
Codesys Development System 3.5.16.0
Codesys Development System 3.5.17.0
7.8
CVSSv3
CVE-2021-21863
A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger...
Codesys Development System 3.5.16.0
Codesys Development System 3.5.17.0
7.3
CVSSv3
CVE-2021-29242
CODESYS Control Runtime system prior to 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.
Codesys Control For Beaglebone Sl
Codesys Control For Empc-a\\/imx6 Sl
Codesys Control For Iot2000 Sl
Codesys Control For Linux Arm Sl
Codesys Control For Linux Sl
Codesys Control For Pfc100 Sl
Codesys Control For Pfc200 Sl
Codesys Control For Plcnext Sl
Codesys Control For Raspberry Pi Sl
Codesys Control For Wago Touch Panels 600 Sl
Codesys Control Rte
Codesys Control Runtime System Toolkit
Codesys Control Win
Codesys Edge Gateway
Codesys Embedded Target Visu Toolkit
Codesys Gateway
Codesys Hmi
Codesys Opc Server
Codesys Plchandler
Codesys Remote Target Visu Toolkit
Codesys Safety Sil
Codesys Simulation Runtime
7.3
CVSSv3
CVE-2023-3670
In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.
Codesys Scripting
Codesys Development System
7.3
CVSSv3
CVE-2023-3662
In CODESYS Development System versions from 3.5.17.0 and before 3.5.19.20 a vulnerability allows for execution of binaries from the current working directory in the users context .
Codesys Development System
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2021-35000
CVE-2024-4439
unauthorized
CVE-2024-0042
CVE-2024-31848
CVE-2023-40694
cache poisoning
CVE-2024-23707
firmware
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »