<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_codesysgmbh/10</id>
  <title>Most recent entries from csaf_codesysgmbh</title>
  <updated>2026-10-02T14:48:17.960620+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-024</id>
    <title>VDE-2023-024 — CODESYS: Vulnerability in CODESYS Development System and CODESYS Scripting</title>
    <updated>2023-07-28T07:45:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-024"/>
    <published>2023-07-28T07:45:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-019</id>
    <title>VDE-2023-019 — CODESYS: Multiple Vulnerabilities in CmpApp CmpAppBP and CmpAppForce</title>
    <updated>2023-08-03T10:42:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CODESYS Control V3 runtime systems are affected by several security vulnerabilities in the communication server implementations for the CODESYS protocol. These may be exploited by authenticated attackers.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-019"/>
    <published>2023-08-03T10:42:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-021</id>
    <title>VDE-2023-021 — CODESYS: Vulnerability in CODESYS Development System allows execution of binaries</title>
    <updated>2023-08-03T10:48:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The CODESYS Development System is vulnerable to the execution of malicious binaries from the current working directory.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-021"/>
    <published>2023-08-03T10:48:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-022</id>
    <title>VDE-2023-022 — CODESYS: Missing integrity check in CODESYS Development System</title>
    <updated>2023-08-03T10:52:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Notification Center of the CODESYS Development System receives messages without ensuring that the message was not modified during transmission. This finally enables MITMs code execution when the user clicks the "Learn More" button.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-022"/>
    <published>2023-08-03T10:52:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-023</id>
    <title>VDE-2023-023 — CODESYS: Missing Brute-Force protection in CODESYS Development System</title>
    <updated>2023-08-03T11:08:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The CODESYS Development System does not limit the number of attempts to guess the password within an import dialog.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-023"/>
    <published>2023-08-03T11:08:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-025</id>
    <title>VDE-2023-025 — CODESYS: Control runtime system memory and integrity check vulnerabilities</title>
    <updated>2023-08-03T11:18:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The CODESYS Control V3 runtime system does not restrict the memory accesses of the PLC application code to the PLC application data and does not sufficiently check the integrity of the application code by default. This could be exploited by authenticated PLC programmers.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-025"/>
    <published>2023-08-03T11:18:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-035</id>
    <title>VDE-2023-035 — CODESYS: Multiple products affected by WIBU Codemeter vulnerability</title>
    <updated>2023-12-05T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several CODESYS setups contain and install vulnerable versions of the WIBU CodeMeter Runtime.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-035"/>
    <published>2023-12-05T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-066</id>
    <title>VDE-2023-066 — CODESYS: OS Command Injection Vulnerability in multiple CODESYS Control products</title>
    <updated>2023-12-05T14:25:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>UPDATE 29.02.2024: Removed "This version is planned for January 2024." from Solution as the updated version is released.On CODESYS Control runtimes running on Linux or QNX operating systems, successfully authenticated PLC programmers can utilize SysFile or CAA-File system libraries to inject calls to additional shell functions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-066"/>
    <published>2023-12-05T14:25:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-046</id>
    <title>VDE-2024-046 — OSCAT: Out-of-bounds read in OSCAT Basic library</title>
    <updated>2024-09-10T14:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Out-of-Bounds read vulnerability in OSCAT Basic Library allows an local, unprivileged attacker to access limited internal data of the PLC which may lead to a crash of the affected service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-046"/>
    <published>2024-09-10T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/advisory2024-05_vde-2024-057</id>
    <title>Advisory2024-05_VDE-2024-057 — CODESYS: CODESYS web server vulnerable to DoS</title>
    <updated>2025-04-03T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The CODESYS web server component of the CODESYS Control runtime system is used by the CODESYS
WebVisu to display visualization screens in a web browser. Receiving a specifically crafted TLS packet on an
HTTPS connection causes the CODESYS web server to crash because the return value of an underlying
function is not checked correctly for such unusual conditions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/advisory2024-05_vde-2024-057"/>
    <published>2024-09-25T21:59:00+00:00</published>
  </entry>
</feed>
