CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

codesys

safety_sil2

20 known vulnerabilities · sorted by CVSS score

CVE-2022-4224
HIGH8.8

In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.

codesys / control_for_beaglebone_sl+15
Network
Published Mar 23, 2023
CVE-2018-20026
HIGH7.5

Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0.

codesys / control_for_beaglebone_sl+17
Network
Published Feb 19, 2019
CVE-2019-9009
HIGH7.5

An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash.

codesys / control_for_beaglebone+13
Network
Published Sep 17, 2019
CVE-2018-20025
HIGH7.5

Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.

codesys / control_for_beaglebone_sl+14
Network
Published Feb 19, 2019
CVE-2023-37545
MEDIUM6.5

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37546, CVE-2023-37547, CVE-2023-37548, CVE-2023-37549, CVE-2023-37550

codesys / control_for_beaglebone_sl+15
Network
Published Aug 3, 2023
CVE-2023-37550
MEDIUM6.5

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546, CVE-2023-37547, CVE-2023-37548 and CVE-2023-37549.

codesys / control_for_beaglebone_sl+15
Network
Published Aug 3, 2023
CVE-2023-37547
MEDIUM6.5

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546, CVE-2023-37548, CVE-2023-37549 and CVE-2023-37550

codesys / control_for_beaglebone_sl+15
Network
Published Aug 3, 2023
CVE-2023-37546
MEDIUM6.5

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37547, CVE-2023-37548, CVE-2023-37549 and CVE-2023-37550

codesys / control_for_beaglebone_sl+15
Network
Published Aug 3, 2023
CVE-2023-37552
MEDIUM6.5

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37553, CVE-2023-37554, CVE-2023-37555 and CVE-2023-37556.

codesys / control_for_beaglebone_sl+15
Network
Published Aug 3, 2023
CVE-2023-37558
MEDIUM6.5

After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37559

codesys / control_for_beaglebone_sl+15
Network
Published Aug 3, 2023
CVE-2023-37555
MEDIUM6.5

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-37554 and CVE-2023-37556.

codesys / control_for_beaglebone_sl+15
Network
Published Aug 3, 2023
CVE-2023-37549
MEDIUM6.5

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546, CVE-2023-37547, CVE-2023-37548 and CVE-2023-37550

codesys / control_for_beaglebone_sl+15
Network
Published Aug 3, 2023
CVE-2023-37551
MEDIUM6.5

In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communication requests can utilize the CmpApp component to download files with any file extensions to the controller. In contrast to the regular file download via CmpFileTransfer, no filtering of certain file types is performed here. As a result, the integrity of the CODESYS control runtime system may be compromised by the files loaded onto the controller.

codesys / control_for_beaglebone_sl+15
Network
Published Aug 3, 2023
CVE-2023-37548
MEDIUM6.5

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546, CVE-2023-37547, CVE-2023-37549 and CVE-2023-37550

codesys / control_for_beaglebone_sl+15
Network
Published Aug 3, 2023
CVE-2023-37553
MEDIUM6.5

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37554, CVE-2023-37555 and CVE-2023-37556.

codesys / control_for_beaglebone_sl+15
Network
Published Aug 3, 2023
CVE-2023-37554
MEDIUM6.5

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-37555 and CVE-2023-37556.

codesys / control_for_beaglebone_sl+15
Network
Published Aug 3, 2023
CVE-2020-7052
MEDIUM6.5

CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.

codesys / control_for_beaglebone+15
Network
Published Jan 24, 2020
CVE-2023-37559
MEDIUM6.5

After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37558

codesys / control_for_beaglebone_sl+15
Network
Published Aug 3, 2023
CVE-2023-37556
MEDIUM6.5

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-37554 and CVE-2023-37555.

codesys / control_for_beaglebone_sl+15
Network
Published Aug 3, 2023
CVE-2023-37557
MEDIUM6.5

After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.

codesys / control_for_beaglebone_sl+15
Network
Published Aug 3, 2023