CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

codesys

development_system_v3

19 known vulnerabilities · sorted by CVSS score

CVE-2018-10612
CRITICAL9.8

In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials.

codesys / control_for_beaglebone_sl+11
Network
Published Jan 29, 2019
CVE-2022-47379
HIGH8.8

An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47387
HIGH8.8

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47380
HIGH8.8

An authenticated remote attacker may use a stack based  out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47381
HIGH8.8

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47384
HIGH8.8

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47383
HIGH8.8

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47389
HIGH8.8

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47388
HIGH8.8

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47390
HIGH8.8

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47386
HIGH8.8

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47382
HIGH8.8

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47385
HIGH8.8

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-4048
HIGH7.7

Inadequate Encryption Strength in CODESYS Development System V3 versions prior to V3.5.18.40 allows an unauthenticated local attacker to access and manipulate code of the encrypted boot application.

codesys / development_system_v3
Local
Published May 15, 2023
CVE-2018-20026
HIGH7.5

Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0.

codesys / control_for_beaglebone_sl+17
Network
Published Feb 19, 2019
CVE-2022-47391
HIGH7.5

In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from invalid addresses leading to a denial of service.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47393
MEDIUM6.5

An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple versions of multiple CODESYS products to force a denial-of-service situation.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47378
MEDIUM6.5

Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated remote attacker may craft specific requests that use the vulnerability leading to a denial-of-service condition.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47392
MEDIUM6.5

An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which can lead to a denial-of-service condition.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023