CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

codesys

edge_gateway

8 known vulnerabilities · sorted by CVSS score

CVE-2022-30791
HIGH7.5

In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected.

codesys / control_for_beaglebone+19
Network
Published Jul 11, 2022
CVE-2022-22517
HIGH7.5

An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.

codesys / control_for_beaglebone_sl+20
Network
Published Apr 7, 2022
CVE-2022-31805
HIGH7.5

In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.

codesys / development_system+9
Network
Published Jun 24, 2022
CVE-2021-29241
HIGH7.5

CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).

codesys / control_for_beaglebone_sl+11
Network
Published May 3, 2021
CVE-2022-30792
HIGH7.5

In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected.

codesys / control_for_beaglebone+19
Network
Published Jul 11, 2022
CVE-2021-29242
HIGH7.3

CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.

codesys / control_for_beaglebone_sl+23
Network
Published May 3, 2021
CVE-2022-22514
HIGH7.1

An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed, this results in a crash.

codesys / control_for_beaglebone_sl+20
Network
Published Apr 7, 2022
CVE-2022-22513
MEDIUM6.5

An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.

codesys / control_for_beaglebone_sl+20
Network
Published Apr 7, 2022