<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_codesysgmbh/10</id>
  <title>Most recent entries from csaf_codesysgmbh</title>
  <updated>2026-10-02T18:50:15.740040+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-024</id>
    <title>VDE-2023-024 — CODESYS: Vulnerability in CODESYS Development System and CODESYS Scripting</title>
    <updated>2023-07-28T07:45:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-024"/>
    <published>2023-07-28T07:45:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-019</id>
    <title>VDE-2023-019 — CODESYS: Multiple Vulnerabilities in CmpApp CmpAppBP and CmpAppForce</title>
    <updated>2023-08-03T10:42:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CODESYS Control V3 runtime systems are affected by several security vulnerabilities in the communication server implementations for the CODESYS protocol. These may be exploited by authenticated attackers.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-019"/>
    <published>2023-08-03T10:42:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-021</id>
    <title>VDE-2023-021 — CODESYS: Vulnerability in CODESYS Development System allows execution of binaries</title>
    <updated>2023-08-03T10:48:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The CODESYS Development System is vulnerable to the execution of malicious binaries from the current working directory.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-021"/>
    <published>2023-08-03T10:48:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-022</id>
    <title>VDE-2023-022 — CODESYS: Missing integrity check in CODESYS Development System</title>
    <updated>2023-08-03T10:52:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Notification Center of the CODESYS Development System receives messages without ensuring that the message was not modified during transmission. This finally enables MITMs code execution when the user clicks the "Learn More" button.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-022"/>
    <published>2023-08-03T10:52:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-023</id>
    <title>VDE-2023-023 — CODESYS: Missing Brute-Force protection in CODESYS Development System</title>
    <updated>2023-08-03T11:08:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The CODESYS Development System does not limit the number of attempts to guess the password within an import dialog.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-023"/>
    <published>2023-08-03T11:08:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-025</id>
    <title>VDE-2023-025 — CODESYS: Control runtime system memory and integrity check vulnerabilities</title>
    <updated>2023-08-03T11:18:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The CODESYS Control V3 runtime system does not restrict the memory accesses of the PLC application code to the PLC application data and does not sufficiently check the integrity of the application code by default. This could be exploited by authenticated PLC programmers.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-025"/>
    <published>2023-08-03T11:18:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-035</id>
    <title>VDE-2023-035 — CODESYS: Multiple products affected by WIBU Codemeter vulnerability</title>
    <updated>2023-12-05T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several CODESYS setups contain and install vulnerable versions of the WIBU CodeMeter Runtime.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-035"/>
    <published>2023-12-05T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-066</id>
    <title>VDE-2023-066 — CODESYS: OS Command Injection Vulnerability in multiple CODESYS Control products</title>
    <updated>2023-12-05T14:25:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>UPDATE 29.02.2024: Removed "This version is planned for January 2024." from Solution as the updated version is released.On CODESYS Control runtimes running on Linux or QNX operating systems, successfully authenticated PLC programmers can utilize SysFile or CAA-File system libraries to inject calls to additional shell functions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-066"/>
    <published>2023-12-05T14:25:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-024</id>
    <title>VDE-2024-024 — CODESYS: Development System V2.3 affected by two vulnerabilities through corrupted project files</title>
    <updated>2025-05-14T13:00:15+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An unauthenticated local attacker may trick a user to open corrupted project files to execute arbitrary code or crash the system due to an out-of-bounds write vulnerability. An unauthenticated local attacker may trick a user to open corrupted project files to crash the system due to use after free vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-024"/>
    <published>2024-05-06T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-027</id>
    <title>VDE-2024-027 — CODESYS: Vulnerability in multiple products through exposure of resource to wrong sphere</title>
    <updated>2025-05-14T13:00:14+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>All legitimate local Microsoft Windows users can read or modify files that are located in the working directory of the affected CODESYS products, even if they are executed under a different user or in the system context.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-027"/>
    <published>2024-06-04T06:00:00+00:00</published>
  </entry>
</feed>
