<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_codesysgmbh</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:13:00 +0000</lastBuildDate>
    <item>
      <title>VDE-2023-024 — CODESYS: Vulnerability in CODESYS Development System and CODESYS Scripting</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-024</link>
      <description>&lt;p&gt;In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-024</guid>
      <pubDate>Fri, 28 Jul 2023 07:45:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-019 — CODESYS: Multiple Vulnerabilities in CmpApp CmpAppBP and CmpAppForce</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-019</link>
      <description>&lt;p&gt;CODESYS Control V3 runtime systems are affected by several security vulnerabilities in the communication server implementations for the CODESYS protocol. These may be exploited by authenticated attackers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CODESYS Control V3 runtime systems are affected by several security vulnerabilities in the communication server implementations for the CODESYS protocol. These may be exploited by authenticated attackers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-019</guid>
      <pubDate>Thu, 03 Aug 2023 10:42:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-021 — CODESYS: Vulnerability in CODESYS Development System allows execution of binaries</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-021</link>
      <description>&lt;p&gt;The CODESYS Development System is vulnerable to the execution of malicious binaries from the current working directory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The CODESYS Development System is vulnerable to the execution of malicious binaries from the current working directory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-021</guid>
      <pubDate>Thu, 03 Aug 2023 10:48:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-022 — CODESYS: Missing integrity check in CODESYS Development System</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-022</link>
      <description>&lt;p&gt;The Notification Center of the CODESYS Development System receives messages without ensuring that the message was not modified during transmission. This finally enables MITMs code execution when the user clicks the &amp;#34;Learn More&amp;#34; button.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Notification Center of the CODESYS Development System receives messages without ensuring that the message was not modified during transmission. This finally enables MITMs code execution when the user clicks the &amp;#34;Learn More&amp;#34; button.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-022</guid>
      <pubDate>Thu, 03 Aug 2023 10:52:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-023 — CODESYS: Missing Brute-Force protection in CODESYS Development System</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-023</link>
      <description>&lt;p&gt;The CODESYS Development System does not limit the number of attempts to guess the password within an import dialog.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The CODESYS Development System does not limit the number of attempts to guess the password within an import dialog.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-023</guid>
      <pubDate>Thu, 03 Aug 2023 11:08:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-025 — CODESYS: Control runtime system memory and integrity check vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-025</link>
      <description>&lt;p&gt;The CODESYS Control V3 runtime system does not restrict the memory accesses of the PLC application code to the PLC application data and does not sufficiently check the integrity of the application code by default. This could be exploited by authenticated PLC programmers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The CODESYS Control V3 runtime system does not restrict the memory accesses of the PLC application code to the PLC application data and does not sufficiently check the integrity of the application code by default. This could be exploited by authenticated PLC programmers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-025</guid>
      <pubDate>Thu, 03 Aug 2023 11:18:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-035 — CODESYS: Multiple products affected by WIBU Codemeter vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-035</link>
      <description>&lt;p&gt;Several CODESYS setups contain and install vulnerable versions of the WIBU CodeMeter Runtime.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several CODESYS setups contain and install vulnerable versions of the WIBU CodeMeter Runtime.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-035</guid>
      <pubDate>Tue, 05 Dec 2023 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-066 — CODESYS: OS Command Injection Vulnerability in multiple CODESYS Control products</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-066</link>
      <description>&lt;p&gt;UPDATE 29.02.2024: Removed &amp;#34;This version is planned for January 2024.&amp;#34; from Solution as the updated version is released.On CODESYS Control runtimes running on Linux or QNX operating systems, successfully authenticated PLC programmers can utilize SysFile or CAA-File system libraries to inject calls to additional shell functions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;UPDATE 29.02.2024: Removed &amp;#34;This version is planned for January 2024.&amp;#34; from Solution as the updated version is released.On CODESYS Control runtimes running on Linux or QNX operating systems, successfully authenticated PLC programmers can utilize SysFile or CAA-File system libraries to inject calls to additional shell functions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-066</guid>
      <pubDate>Tue, 05 Dec 2023 14:25:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-024 — CODESYS: Development System V2.3 affected by two vulnerabilities through corrupted project files</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-024</link>
      <description>&lt;p&gt;An unauthenticated local attacker may trick a user to open corrupted project files to execute arbitrary code or crash the system due to an out-of-bounds write vulnerability. An unauthenticated local attacker may trick a user to open corrupted project files to crash the system due to use after free vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unauthenticated local attacker may trick a user to open corrupted project files to execute arbitrary code or crash the system due to an out-of-bounds write vulnerability. An unauthenticated local attacker may trick a user to open corrupted project files to crash the system due to use after free vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-024</guid>
      <pubDate>Mon, 06 May 2024 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-027 — CODESYS: Vulnerability in multiple products through exposure of resource to wrong sphere</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-027</link>
      <description>&lt;p&gt;All legitimate local Microsoft Windows users can read or modify files that are located in the working directory of the affected CODESYS products, even if they are executed under a different user or in the system context.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;All legitimate local Microsoft Windows users can read or modify files that are located in the working directory of the affected CODESYS products, even if they are executed under a different user or in the system context.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-027</guid>
      <pubDate>Tue, 04 Jun 2024 06:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
