Codesys Control Rte 3.5.14.40

CPE Details

Codesys Control Rte 3.5.14.40
3.5.14.40
2019-09-17
14h26 +00:00
2021-02-25
20h52 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:codesys:control_rte:3.5.14.40:*:*:*:*:*:*:*

Informations

Vendor

codesys

Product

control_rte

Version

3.5.14.40

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-29242 2021-05-03 11h56 +00:00 CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.
7.3
High
CVE-2020-12068 2020-05-14 18h29 +00:00 An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.
6.5
Medium
CVE-2020-10245 2020-03-26 02h45 +00:00 CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.
9.8
Critical
CVE-2020-7052 2020-01-24 18h31 +00:00 CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.
6.5
Medium
CVE-2019-18858 2019-11-20 16h04 +00:00 CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.
9.8
Critical
CVE-2019-13542 2019-09-17 16h56 +00:00 3S-Smart Software Solutions GmbH CODESYS V3 OPC UA Server, all versions 3.5.11.0 to 3.5.15.0, allows an attacker to send crafted requests from a trusted OPC UA client that cause a NULL pointer dereference, which may trigger a denial-of-service condition.
6.5
Medium
CVE-2019-9009 2019-09-17 13h34 +00:00 An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash.
7.5
High