Search

Find a vulnerability

Search criteria

    40 vulnerabilities found for Gateway by CODESYS

    CVE-2026-76992 (GCVE-0-2026-76992)

    Vulnerability from nvd – Published: 2026-09-30 11:07 – Updated: 2026-09-30 15:28
    VLAI
    Title
    Uncontrolled Memory Allocation in CODESYS Gateway Client
    Summary
    The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 14:48 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    References
    Impacted products
    Vendor Product Version
    CODESYS Development System 3 Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS Gateway Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS Edge Gateway for Windows Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS HMI (SL) Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS OPC DA Server SL Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS PLCHandler Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS Runtime Toolkit Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS Edge Gateway for Linux Affected: 3.15.0.0 , < 4.23.0.0 (generic)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-76992",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T14:48:15.816736Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T15:28:07.834Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Development System 3",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Edge Gateway for Windows",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "HMI (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "OPC DA Server SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "PLCHandler",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Runtime Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Edge Gateway for Linux",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "4.23.0.0",
                  "status": "affected",
                  "version": "3.15.0.0",
                  "versionType": "generic"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_development_system_3:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_gateway:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_edge_gateway_for_windows:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_hmi_sl:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_opc_da_server_sl:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_plchandler:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_runtime_toolkit:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_edge_gateway_for_linux:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "4.23.0.0",
                      "versionStartIncluding": "3.15.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Delta Electronics Inc."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.\u003c/p\u003e"
                }
              ],
              "value": "The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T11:07:45.751Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-094/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-094",
            "defect": [
              "CERT@VDE#642222"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Uncontrolled Memory Allocation in CODESYS Gateway Client",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-76992",
        "datePublished": "2026-09-30T11:07:45.751Z",
        "dateReserved": "2026-08-20T06:57:08.465Z",
        "dateUpdated": "2026-09-30T15:28:07.834Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-5751 (GCVE-0-2023-5751)

    Vulnerability from nvd – Published: 2024-06-04 08:54 – Updated: 2024-08-02 08:07
    VLAI
    Title
    CODESYS: Development system prone to DoS through exposure of resource to wrong sphere
    Summary
    A local attacker with low privileges can read and modify any users files and cause a DoS in the working directory of the affected products due to exposure of resource to wrong sphere.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-04 14:51 UTC
    CWE
    • CWE-668 - Exposure of Resource to Wrong Sphere
    Impacted products
    Vendor Product Version
    CODESYS CODESYS Control Win (SL) Affected: 0 , < 3.5.20.10 (semver)
    Create a notification for this product.
    CODESYS CODESYS Development System V3 Affected: 0 , < 3.5.20.10 (semver)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Windows Affected: 0 , < 3.5.20.10 (semver)
    Create a notification for this product.
    CODESYS CODESYS Gateway for Windows Affected: 0 , < 3.5.20.10 (semver)
    Create a notification for this product.
    CODESYS CODESYS HMI (SL) Affected: 0 , < 3.5.20.10 (semver)
    Create a notification for this product.
    codesys control_win_sl Affected: 0 , < 3.5.20.10 (custom)
        cpe:2.3:a:codesys:control_win_sl:0:*:*:*:*:*:*:*
    Create a notification for this product.
    codesys development_system_v3 Affected: 0 , < 3.5.20.10 (custom)
        cpe:2.3:a:codesys:development_system_v3:0:*:*:*:*:*:*:*
    Create a notification for this product.
    codesys edge_gateway Affected: 0 , < 3.5.20.10 (custom)
        cpe:2.3:a:codesys:edge_gateway:0:*:*:*:*:*:*:*
    Create a notification for this product.
    codesys gateway Affected: 0 , < 3.5.20.10 (custom)
        cpe:2.3:a:codesys:gateway:0:*:*:*:*:*:*:*
    Create a notification for this product.
    codesys hmi_sl Affected: 0 , < 3.5.20.10 (custom)
        cpe:2.3:a:codesys:hmi_sl:0:*:*:*:*:*:*:*
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:codesys:control_win_sl:0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "control_win_sl",
                "vendor": "codesys",
                "versions": [
                  {
                    "lessThan": "3.5.20.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:codesys:development_system_v3:0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "development_system_v3",
                "vendor": "codesys",
                "versions": [
                  {
                    "lessThan": "3.5.20.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:codesys:edge_gateway:0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "edge_gateway",
                "vendor": "codesys",
                "versions": [
                  {
                    "lessThan": "3.5.20.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:codesys:gateway:0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "gateway",
                "vendor": "codesys",
                "versions": [
                  {
                    "lessThan": "3.5.20.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:codesys:hmi_sl:0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "hmi_sl",
                "vendor": "codesys",
                "versions": [
                  {
                    "lessThan": "3.5.20.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-5751",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-04T14:51:51.731368Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-04T17:28:31.539Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T08:07:32.848Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2024-027"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=18354\u0026token=f3e92a942c3a2f90c272a5ded7598c6a0b5f4924\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Control Win (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.20.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Development System V3",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.20.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Edge Gateway for Windows",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.20.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Gateway for Windows",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.20.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS HMI (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.20.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "joker63"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A local attacker with low privileges can read and modify any users files and cause a DoS in the working directory of the affected products due to exposure of resource to wrong sphere.\u0026nbsp;\u003cbr\u003e"
                }
              ],
              "value": "A local attacker with low privileges can read and modify any users files and cause a DoS in the working directory of the affected products due to exposure of resource to wrong sphere.\u00a0\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-668",
                  "description": "CWE-668 Exposure of Resource to Wrong Sphere",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-04T08:54:22.046Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-027"
            },
            {
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=18354\u0026token=f3e92a942c3a2f90c272a5ded7598c6a0b5f4924\u0026download="
            }
          ],
          "source": {
            "advisory": "VDE-2024-027",
            "defect": [
              "CERT@VDE#64603"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "CODESYS: Development system prone to DoS through exposure of resource to wrong sphere",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2023-5751",
        "datePublished": "2024-06-04T08:54:22.046Z",
        "dateReserved": "2023-10-24T11:46:25.505Z",
        "dateUpdated": "2024-08-02T08:07:32.848Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-30792 (GCVE-0-2022-30792)

    Vulnerability from nvd – Published: 2022-07-11 10:40 – Updated: 2024-09-16 23:05
    VLAI
    Title
    CODESYS: CmpChannelServer, CmpChannelServerEmbedded allow unauthenticated attackers to block all their available communication channels
    Summary
    In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected.
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    References
    Impacted products
    Vendor Product Version
    CODESYS CODESYS Control RTE (SL) Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control RTE (for Beckhoff CX) SL Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control Win (SL) Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Gateway Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Windows Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS HMI (SL) Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Development System V3 Affected: V3 , < V3.5.18.10 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control Runtime System Toolkit Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Embedded Target Visu Toolkit Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Remote Target Visu Toolkit Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for BeagleBone SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Beckhoff CX9020 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for emPC-A/iMX6 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for IOT2000 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Linux SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PFC100 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PFC200 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PLCnext SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Raspberry Pi SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for WAGO Touch Panels 600 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Linux Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    Date Public
    2022-07-08 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T07:03:38.599Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17128\u0026token=bee4d8a57f19be289d623ec90135493b5f9179e3\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CODESYS Control RTE (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control RTE (for Beckhoff CX) SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control Win (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Gateway",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Edge Gateway for Windows",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS HMI (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Development System V3",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.10",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control Runtime System Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Embedded Target Visu Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Remote Target Visu Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for BeagleBone SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Beckhoff CX9020 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for emPC-A/iMX6 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for IOT2000 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Linux SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PFC100 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PFC200 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PLCnext SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Raspberry Pi SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for WAGO Touch Panels 600 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Edge Gateway for Linux",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-07-08T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "CWE-400 Uncontrolled Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-07-11T10:40:43.000Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17128\u0026token=bee4d8a57f19be289d623ec90135493b5f9179e3\u0026download="
            }
          ],
          "source": {
            "defect": [
              "CERT@VDE#",
              "64130"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "CODESYS: CmpChannelServer, CmpChannelServerEmbedded allow unauthenticated attackers to block all their available communication channels",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "info@cert.vde.com",
              "DATE_PUBLIC": "2022-07-08T06:00:00.000Z",
              "ID": "CVE-2022-30792",
              "STATE": "PUBLIC",
              "TITLE": "CODESYS: CmpChannelServer, CmpChannelServerEmbedded allow unauthenticated attackers to block all their available communication channels"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CODESYS Control RTE (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control RTE (for Beckhoff CX) SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control Win (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Gateway",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS HMI (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Development System V3",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.10"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control Runtime System Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Embedded Target Visu Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Remote Target Visu Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for BeagleBone SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Beckhoff CX9020 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for emPC-A/iMX6 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for IOT2000 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Linux SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PFC100 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PFC200 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PLCnext SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Raspberry Pi SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for WAGO Touch Panels 600 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Linux",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "CODESYS"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-400 Uncontrolled Resource Consumption"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17128\u0026token=bee4d8a57f19be289d623ec90135493b5f9179e3\u0026download=",
                  "refsource": "CONFIRM",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17128\u0026token=bee4d8a57f19be289d623ec90135493b5f9179e3\u0026download="
                }
              ]
            },
            "source": {
              "defect": [
                "CERT@VDE#",
                "64130"
              ],
              "discovery": "UNKNOWN"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2022-30792",
        "datePublished": "2022-07-11T10:40:43.935Z",
        "dateReserved": "2022-05-16T00:00:00.000Z",
        "dateUpdated": "2024-09-16T23:05:31.037Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-30791 (GCVE-0-2022-30791)

    Vulnerability from nvd – Published: 2022-07-11 10:40 – Updated: 2024-09-16 16:48
    VLAI
    Title
    CODESYS V3: CmpBlkDrvTcp allows unauthenticated attackers to block all its available TCP connections
    Summary
    In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected.
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    References
    Impacted products
    Vendor Product Version
    CODESYS CODESYS Control RTE (SL) Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control RTE (for Beckhoff CX) SL Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control Win (SL) Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Gateway Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Windows Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS HMI (SL) Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Development System V3 Affected: V3 , < V3.5.18.10 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control Runtime System Toolkit Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Embedded Target Visu Toolkit Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Remote Target Visu Toolkit Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for BeagleBone SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Beckhoff CX9020 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for emPC-A/iMX6 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for IOT2000 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Linux SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PFC100 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PFC200 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PLCnext SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Raspberry Pi SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for WAGO Touch Panels 600 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Linux Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    Date Public
    2022-07-08 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T07:03:38.611Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17128\u0026token=bee4d8a57f19be289d623ec90135493b5f9179e3\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CODESYS Control RTE (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control RTE (for Beckhoff CX) SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control Win (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Gateway",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Edge Gateway for Windows",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS HMI (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Development System V3",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.10",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control Runtime System Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Embedded Target Visu Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Remote Target Visu Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for BeagleBone SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Beckhoff CX9020 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for emPC-A/iMX6 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for IOT2000 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Linux SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PFC100 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PFC200 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PLCnext SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Raspberry Pi SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for WAGO Touch Panels 600 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Edge Gateway for Linux",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-07-08T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "CWE-400 Uncontrolled Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-07-11T10:40:38.000Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17128\u0026token=bee4d8a57f19be289d623ec90135493b5f9179e3\u0026download="
            }
          ],
          "source": {
            "defect": [
              "CERT@VDE#",
              "64129"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "CODESYS V3: CmpBlkDrvTcp allows unauthenticated attackers to block all its available TCP connections",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "info@cert.vde.com",
              "DATE_PUBLIC": "2022-07-08T06:00:00.000Z",
              "ID": "CVE-2022-30791",
              "STATE": "PUBLIC",
              "TITLE": "CODESYS V3: CmpBlkDrvTcp allows unauthenticated attackers to block all its available TCP connections"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CODESYS Control RTE (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control RTE (for Beckhoff CX) SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control Win (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Gateway",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS HMI (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Development System V3",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.10"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control Runtime System Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Embedded Target Visu Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Remote Target Visu Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for BeagleBone SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Beckhoff CX9020 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for emPC-A/iMX6 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for IOT2000 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Linux SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PFC100 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PFC200 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PLCnext SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Raspberry Pi SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for WAGO Touch Panels 600 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Linux",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "CODESYS"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-400 Uncontrolled Resource Consumption"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17128\u0026token=bee4d8a57f19be289d623ec90135493b5f9179e3\u0026download=",
                  "refsource": "CONFIRM",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17128\u0026token=bee4d8a57f19be289d623ec90135493b5f9179e3\u0026download="
                }
              ]
            },
            "source": {
              "defect": [
                "CERT@VDE#",
                "64129"
              ],
              "discovery": "UNKNOWN"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2022-30791",
        "datePublished": "2022-07-11T10:40:38.913Z",
        "dateReserved": "2022-05-16T00:00:00.000Z",
        "dateUpdated": "2024-09-16T16:48:31.565Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-31805 (GCVE-0-2022-31805)

    Vulnerability from nvd – Published: 2022-06-24 07:46 – Updated: 2024-09-16 18:55
    VLAI
    Title
    Insecure transmission of credentials
    Summary
    In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
    CWE
    • CWE-523 - Unprotected Transport of Credentials
    References
    Date Public
    2022-06-22 22:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T07:26:01.086Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17140\u0026token=6aa2c5c4a8b83b8b09936fefed5b0b11f9d2cc6c\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Development System",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V2.3.9.69",
                  "status": "affected",
                  "version": "V2",
                  "versionType": "custom"
                },
                {
                  "lessThan": "V3.5.18.30",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Gateway Client",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V2.3.9.38",
                  "status": "affected",
                  "version": "V2",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Gateway Server",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V2.3.9.38",
                  "status": "affected",
                  "version": "V2",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Web server",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V1.1.9.23",
                  "status": "affected",
                  "version": "V1",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS SP Realtime NT",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V2.3.7.30",
                  "status": "affected",
                  "version": "V2",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS PLCWinNT",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V2.4.7.57",
                  "status": "affected",
                  "version": "V2",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Runtime Toolkit 32 bit full",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V2.4.7.57",
                  "status": "affected",
                  "version": "V2",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Edge Gateway for Windows",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.30",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS HMI (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.30",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS OPC DA Server SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.30",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS PLCHandler",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.30",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Gateway",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.30",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-06-22T22:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIn the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.\u003c/p\u003e"
                }
              ],
              "value": "In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-523",
                  "description": "CWE-523 Unprotected Transport of Credentials",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-05-09T12:54:39.506Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17140\u0026token=6aa2c5c4a8b83b8b09936fefed5b0b11f9d2cc6c\u0026download="
            }
          ],
          "source": {
            "defect": [
              "CERT@VDE#",
              "64140"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Insecure transmission of credentials",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "info@cert.vde.com",
              "DATE_PUBLIC": "2022-06-23T10:00:00.000Z",
              "ID": "CVE-2022-31805",
              "STATE": "PUBLIC",
              "TITLE": "Insecure transmission of credentials"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CODESYS Development System",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V2",
                                "version_value": "V2.3.9.69"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Gateway Client",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V2",
                                "version_value": "V2.3.9.38"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Gateway Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V2",
                                "version_value": "V2.3.9.38"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Web server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V1",
                                "version_value": "V1.1.9.23"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS SP Realtime NT",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V2",
                                "version_value": "V2.3.7.30"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS PLCWinNT",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V2",
                                "version_value": "V2.4.7.57"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Runtime Toolkit 32 bit full",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V2",
                                "version_value": "V2.4.7.57"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS HMI (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS OPC DA Server SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS PLCHandler",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Gateway",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "CODESYS"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-523 Unprotected Transport of Credentials"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17140\u0026token=6aa2c5c4a8b83b8b09936fefed5b0b11f9d2cc6c\u0026download=",
                  "refsource": "CONFIRM",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17140\u0026token=6aa2c5c4a8b83b8b09936fefed5b0b11f9d2cc6c\u0026download="
                }
              ]
            },
            "source": {
              "defect": [
                "CERT@VDE#",
                "64140"
              ],
              "discovery": "UNKNOWN"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2022-31805",
        "datePublished": "2022-06-24T07:46:15.076Z",
        "dateReserved": "2022-05-30T00:00:00.000Z",
        "dateUpdated": "2024-09-16T18:55:26.939Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-31804 (GCVE-0-2022-31804)

    Vulnerability from nvd – Published: 2022-06-24 07:46 – Updated: 2024-09-16 20:16
    VLAI
    Title
    CODESYS Gateway server prone to denial of service attack due to excessive memory allocation
    Summary
    The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated attacker may allocate an arbitrary amount of memory, which may lead to a crash of the Gateway due to an out-of-memory condition.
    CWE
    • CWE-789 - Memory Allocation with Excessive Size Value
    References
    Impacted products
    Vendor Product Version
    CODESYS CODESYS Gateway Server V2 Affected: unspecified , < V2.3.9.38 (custom)
    Create a notification for this product.
    Date Public
    2022-06-09 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T07:26:01.284Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CODESYS Gateway Server V2",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V2.3.9.38",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-06-09T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated attacker may allocate an arbitrary amount of memory, which may lead to a crash of the Gateway due to an out-of-memory condition."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-789",
                  "description": "CWE-789: Memory Allocation with Excessive Size Value",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-06-24T07:46:12.000Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download="
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CODESYS Gateway server prone to denial of service attack due to excessive memory allocation",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "info@cert.vde.com",
              "DATE_PUBLIC": "2022-06-09T08:02:00.000Z",
              "ID": "CVE-2022-31804",
              "STATE": "PUBLIC",
              "TITLE": "CODESYS Gateway server prone to denial of service attack due to excessive memory allocation"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CODESYS Gateway Server V2",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "V2.3.9.38"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "CODESYS"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated attacker may allocate an arbitrary amount of memory, which may lead to a crash of the Gateway due to an out-of-memory condition."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-789: Memory Allocation with Excessive Size Value"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download=",
                  "refsource": "CONFIRM",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download="
                }
              ]
            },
            "source": {
              "discovery": "UNKNOWN"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2022-31804",
        "datePublished": "2022-06-24T07:46:13.080Z",
        "dateReserved": "2022-05-30T00:00:00.000Z",
        "dateUpdated": "2024-09-16T20:16:34.660Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-31803 (GCVE-0-2022-31803)

    Vulnerability from nvd – Published: 2022-06-24 07:46 – Updated: 2024-09-16 20:01
    VLAI
    Title
    CODESYS Gateway Server V2 prone to Denial of Service Attack
    Summary
    In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all available TCP connections and prevent legitimate users or clients from establishing a new connection to the CODESYS Gateway Server V2. Existing connections are not affected and therefore remain intact.
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    References
    Impacted products
    Vendor Product Version
    CODESYS CODESYS Gateway Server V2 Affected: V2 , < V2.3.9.38 (custom)
    Create a notification for this product.
    Date Public
    2022-06-09 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T07:26:01.247Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CODESYS Gateway Server V2",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V2.3.9.38",
                  "status": "affected",
                  "version": "V2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-06-09T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all available TCP connections and prevent legitimate users or clients from establishing a new connection to the CODESYS Gateway Server V2. Existing connections are not affected and therefore remain intact."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "CWE-400 Uncontrolled Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-06-24T07:46:11.000Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download="
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CODESYS Gateway Server V2 prone to Denial of Service Attack",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "info@cert.vde.com",
              "DATE_PUBLIC": "2022-06-09T07:54:00.000Z",
              "ID": "CVE-2022-31803",
              "STATE": "PUBLIC",
              "TITLE": "CODESYS Gateway Server V2 prone to Denial of Service Attack"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CODESYS Gateway Server V2",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V2",
                                "version_value": "V2.3.9.38"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "CODESYS"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all available TCP connections and prevent legitimate users or clients from establishing a new connection to the CODESYS Gateway Server V2. Existing connections are not affected and therefore remain intact."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-400 Uncontrolled Resource Consumption"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download=",
                  "refsource": "CONFIRM",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download="
                }
              ]
            },
            "source": {
              "discovery": "UNKNOWN"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2022-31803",
        "datePublished": "2022-06-24T07:46:11.188Z",
        "dateReserved": "2022-05-30T00:00:00.000Z",
        "dateUpdated": "2024-09-16T20:01:21.315Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-31802 (GCVE-0-2022-31802)

    Vulnerability from nvd – Published: 2022-06-24 07:46 – Updated: 2024-09-17 00:32
    VLAI
    Title
    Partial string comparison in CODESYS gateway server
    Summary
    In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer real CODESYS Gateway password.
    CWE
    • CWE-187 - Partial String Comparison
    References
    Impacted products
    Vendor Product Version
    CODESYS CODESYS Gateway Server V2 Affected: V2 , < V2.3.9.38 (custom)
    Create a notification for this product.
    Date Public
    2022-06-09 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T07:26:01.284Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CODESYS Gateway Server V2",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V2.3.9.38",
                  "status": "affected",
                  "version": "V2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-06-09T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer real CODESYS Gateway password."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-187",
                  "description": "CWE-187 Partial String Comparison",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-06-24T07:46:09.000Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download="
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Partial string comparison in CODESYS gateway server",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "info@cert.vde.com",
              "DATE_PUBLIC": "2022-06-09T07:38:00.000Z",
              "ID": "CVE-2022-31802",
              "STATE": "PUBLIC",
              "TITLE": "Partial string comparison in CODESYS gateway server"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CODESYS Gateway Server V2",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V2",
                                "version_value": "V2.3.9.38"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "CODESYS"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer real CODESYS Gateway password."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-187 Partial String Comparison"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download=",
                  "refsource": "CONFIRM",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download="
                }
              ]
            },
            "source": {
              "discovery": "UNKNOWN"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2022-31802",
        "datePublished": "2022-06-24T07:46:09.625Z",
        "dateReserved": "2022-05-30T00:00:00.000Z",
        "dateUpdated": "2024-09-17T00:32:18.904Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-22517 (GCVE-0-2022-22517)

    Vulnerability from nvd – Published: 2022-04-07 18:21 – Updated: 2024-09-16 22:16
    VLAI
    Title
    Communication Components in multiple CODESYS products vulnerable to communication channel disruption
    Summary
    An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.
    CWE
    • CWE-334 - Small Space of Random Values
    References
    Impacted products
    Vendor Product Version
    CODESYS CODESYS Control RTE (SL) Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control RTE (for Beckhoff CX) SL Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control Win (SL) Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Gateway Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Windows Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS HMI (SL) Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Development System V3 Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control Runtime System Toolkit Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Embedded Target Visu Toolkit Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Remote Target Visu Toolkit Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for BeagleBone SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Beckhoff CX9020 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for emPC-A/iMX6 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for IOT2000 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Linux SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PFC100 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PFC200 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PLCnext SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Raspberry Pi SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for WAGO Touch Panels 600 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Linux Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS OPC DA Server SL Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS PLCHandler Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    Date Public
    2022-04-06 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T03:14:55.454Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17091\u0026token=c450f8bbbd838c647d102f359356386c6ea5aeca\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CODESYS Control RTE (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control RTE (for Beckhoff CX) SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control Win (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Gateway",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Edge Gateway for Windows",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS HMI (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Development System V3",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control Runtime System Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Embedded Target Visu Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Remote Target Visu Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for BeagleBone SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Beckhoff CX9020 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for emPC-A/iMX6 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for IOT2000 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Linux SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PFC100 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PFC200 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PLCnext SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Raspberry Pi SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for WAGO Touch Panels 600 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Edge Gateway for Linux",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS OPC DA Server SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS PLCHandler",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-04-06T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-334",
                  "description": "CWE-334 Small Space of Random Values",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-04-07T18:21:19.000Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17091\u0026token=c450f8bbbd838c647d102f359356386c6ea5aeca\u0026download="
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Communication Components in multiple CODESYS products vulnerable to communication channel disruption",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "info@cert.vde.com",
              "DATE_PUBLIC": "2022-04-06T10:00:00.000Z",
              "ID": "CVE-2022-22517",
              "STATE": "PUBLIC",
              "TITLE": "Communication Components in multiple CODESYS products vulnerable to communication channel disruption"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CODESYS Control RTE (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control RTE (for Beckhoff CX) SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control Win (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Gateway",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS HMI (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Development System V3",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control Runtime System Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Embedded Target Visu Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Remote Target Visu Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for BeagleBone SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Beckhoff CX9020 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for emPC-A/iMX6 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for IOT2000 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Linux SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PFC100 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PFC200 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PLCnext SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Raspberry Pi SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for WAGO Touch Panels 600 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Linux",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS OPC DA Server SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS PLCHandler",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "CODESYS"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-334 Small Space of Random Values"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17091\u0026token=c450f8bbbd838c647d102f359356386c6ea5aeca\u0026download=",
                  "refsource": "MISC",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17091\u0026token=c450f8bbbd838c647d102f359356386c6ea5aeca\u0026download="
                }
              ]
            },
            "source": {
              "discovery": "UNKNOWN"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2022-22517",
        "datePublished": "2022-04-07T18:21:20.091Z",
        "dateReserved": "2022-01-03T00:00:00.000Z",
        "dateUpdated": "2024-09-16T22:16:04.923Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-22514 (GCVE-0-2022-22514)

    Vulnerability from nvd – Published: 2022-04-07 18:21 – Updated: 2024-09-17 03:03
    VLAI
    Title
    Untrusted Pointer Dereference in multiple CODESYS products can lead to a DoS.
    Summary
    An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed, this results in a crash.
    CWE
    • CWE-822 - Untrusted Pointer Dereference
    References
    Impacted products
    Vendor Product Version
    CODESYS CODESYS Control RTE (SL) Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control RTE (for Beckhoff CX) SL Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control Win (SL) Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Gateway Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Windows Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS HMI (SL) Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Development System V3 Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control Runtime System Toolkit Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Embedded Target Visu Toolkit Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Remote Target Visu Toolkit Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for BeagleBone SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Beckhoff CX9020 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for emPC-A/iMX6 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for IOT2000 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Linux SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PFC100 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PFC200 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PLCnext SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Raspberry Pi SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for WAGO Touch Panels 600 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Linux Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    Date Public
    2022-04-06 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T03:14:55.446Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17093\u0026token=15cd8424832ea10dcd4873a409a09a539ee381ca\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CODESYS Control RTE (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control RTE (for Beckhoff CX) SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control Win (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Gateway",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Edge Gateway for Windows",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS HMI (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Development System V3",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control Runtime System Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Embedded Target Visu Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Remote Target Visu Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for BeagleBone SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Beckhoff CX9020 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for emPC-A/iMX6 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for IOT2000 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Linux SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PFC100 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PFC200 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PLCnext SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Raspberry Pi SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for WAGO Touch Panels 600 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Edge Gateway for Linux",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-04-06T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed, this results in a crash."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-822",
                  "description": "CWE-822: Untrusted Pointer Dereference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-04-27T05:55:11.000Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17093\u0026token=15cd8424832ea10dcd4873a409a09a539ee381ca\u0026download="
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Untrusted Pointer Dereference in multiple CODESYS products can lead to a DoS.",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "info@cert.vde.com",
              "DATE_PUBLIC": "2022-04-06T10:00:00.000Z",
              "ID": "CVE-2022-22514",
              "STATE": "PUBLIC",
              "TITLE": "Untrusted Pointer Dereference in multiple CODESYS products can lead to a DoS."
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CODESYS Control RTE (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control RTE (for Beckhoff CX) SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control Win (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Gateway",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS HMI (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Development System V3",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control Runtime System Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Embedded Target Visu Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Remote Target Visu Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for BeagleBone SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Beckhoff CX9020 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for emPC-A/iMX6 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for IOT2000 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Linux SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PFC100 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PFC200 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PLCnext SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Raspberry Pi SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for WAGO Touch Panels 600 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Linux",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "CODESYS"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed, this results in a crash."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-822: Untrusted Pointer Dereference"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17093\u0026token=15cd8424832ea10dcd4873a409a09a539ee381ca\u0026download=",
                  "refsource": "MISC",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17093\u0026token=15cd8424832ea10dcd4873a409a09a539ee381ca\u0026download="
                }
              ]
            },
            "source": {
              "discovery": "UNKNOWN"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2022-22514",
        "datePublished": "2022-04-07T18:21:14.309Z",
        "dateReserved": "2022-01-03T00:00:00.000Z",
        "dateUpdated": "2024-09-17T03:03:50.086Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-22513 (GCVE-0-2022-22513)

    Vulnerability from nvd – Published: 2022-04-07 18:21 – Updated: 2024-09-17 04:29
    VLAI
    Title
    Null Pointer Dereference in multiple CODESYS products can lead to a DoS.
    Summary
    An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.
    CWE
    • CWE-476 - NULL Pointer Dereference
    References
    Impacted products
    Vendor Product Version
    CODESYS CODESYS Control RTE (SL) Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control RTE (for Beckhoff CX) SL Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control Win (SL) Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Gateway Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Windows Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS HMI (SL) Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Development System V3 Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control Runtime System Toolkit Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Embedded Target Visu Toolkit Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Remote Target Visu Toolkit Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for BeagleBone SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Beckhoff CX9020 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for emPC-A/iMX6 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for IOT2000 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Linux SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PFC100 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PFC200 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PLCnext SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Raspberry Pi SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for WAGO Touch Panels 600 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Linux Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    Date Public
    2022-04-06 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T03:14:55.460Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17093\u0026token=15cd8424832ea10dcd4873a409a09a539ee381ca\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CODESYS Control RTE (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control RTE (for Beckhoff CX) SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control Win (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Gateway",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Edge Gateway for Windows",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS HMI (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Development System V3",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control Runtime System Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Embedded Target Visu Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Remote Target Visu Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for BeagleBone SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Beckhoff CX9020 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for emPC-A/iMX6 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for IOT2000 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Linux SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PFC100 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PFC200 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PLCnext SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Raspberry Pi SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for WAGO Touch Panels 600 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Edge Gateway for Linux",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-04-06T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-476",
                  "description": "CWE-476 NULL Pointer Dereference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-04-27T05:55:10.000Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17093\u0026token=15cd8424832ea10dcd4873a409a09a539ee381ca\u0026download="
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Null Pointer Dereference in multiple CODESYS products can lead to a DoS.",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "info@cert.vde.com",
              "DATE_PUBLIC": "2022-04-06T10:00:00.000Z",
              "ID": "CVE-2022-22513",
              "STATE": "PUBLIC",
              "TITLE": "Null Pointer Dereference in multiple CODESYS products can lead to a DoS."
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CODESYS Control RTE (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control RTE (for Beckhoff CX) SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control Win (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Gateway",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS HMI (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Development System V3",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control Runtime System Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Embedded Target Visu Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Remote Target Visu Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for BeagleBone SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Beckhoff CX9020 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for emPC-A/iMX6 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for IOT2000 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Linux SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PFC100 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PFC200 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PLCnext SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Raspberry Pi SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for WAGO Touch Panels 600 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Linux",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "CODESYS"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-476 NULL Pointer Dereference"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17093\u0026token=15cd8424832ea10dcd4873a409a09a539ee381ca\u0026download=",
                  "refsource": "MISC",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17093\u0026token=15cd8424832ea10dcd4873a409a09a539ee381ca\u0026download="
                }
              ]
            },
            "source": {
              "discovery": "UNKNOWN"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2022-22513",
        "datePublished": "2022-04-07T18:21:12.792Z",
        "dateReserved": "2022-01-03T00:00:00.000Z",
        "dateUpdated": "2024-09-17T04:29:14.122Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-36764 (GCVE-0-2021-36764)

    Vulnerability from nvd – Published: 2021-08-04 13:35 – Updated: 2024-08-04 01:01
    VLAI
    Summary
    In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products and may result in a denial-of-service condition.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T01:01:59.256Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=16804\u0026token=d8c89c887979b22fdfc9fd5c3aa3804bbb1ddbff\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products and may result in a denial-of-service condition."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-08-04T13:35:31.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=16804\u0026token=d8c89c887979b22fdfc9fd5c3aa3804bbb1ddbff\u0026download="
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2021-36764",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products and may result in a denial-of-service condition."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=16804\u0026token=d8c89c887979b22fdfc9fd5c3aa3804bbb1ddbff\u0026download=",
                  "refsource": "CONFIRM",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=16804\u0026token=d8c89c887979b22fdfc9fd5c3aa3804bbb1ddbff\u0026download="
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2021-36764",
        "datePublished": "2021-08-04T13:35:31.000Z",
        "dateReserved": "2021-07-16T00:00:00.000Z",
        "dateUpdated": "2024-08-04T01:01:59.256Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-29242 (GCVE-0-2021-29242)

    Vulnerability from nvd – Published: 2021-05-03 13:56 – Updated: 2024-08-03 22:02
    VLAI
    Summary
    CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.
    Severity
    No CVSS data available.
    CWE
    • n/a
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T22:02:51.582Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.codesys.com/security/security-reports.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=14640\u0026token=623b6fceb0579ef0f7505e29beefa5b3f8ac7873\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router\u0027s addressing scheme and may re-route, add, remove or change low level communication packages."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-05-03T13:56:06.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://customers.codesys.com/index.php"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.codesys.com/security/security-reports.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=14640\u0026token=623b6fceb0579ef0f7505e29beefa5b3f8ac7873\u0026download="
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2021-29242",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router\u0027s addressing scheme and may re-route, add, remove or change low level communication packages."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php",
                  "refsource": "MISC",
                  "url": "https://customers.codesys.com/index.php"
                },
                {
                  "name": "https://www.codesys.com/security/security-reports.html",
                  "refsource": "MISC",
                  "url": "https://www.codesys.com/security/security-reports.html"
                },
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=14640\u0026token=623b6fceb0579ef0f7505e29beefa5b3f8ac7873\u0026download=",
                  "refsource": "MISC",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=14640\u0026token=623b6fceb0579ef0f7505e29beefa5b3f8ac7873\u0026download="
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2021-29242",
        "datePublished": "2021-05-03T13:56:06.000Z",
        "dateReserved": "2021-03-25T00:00:00.000Z",
        "dateUpdated": "2024-08-03T22:02:51.582Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-29241 (GCVE-0-2021-29241)

    Vulnerability from nvd – Published: 2021-05-03 13:17 – Updated: 2026-05-29 14:01
    VLAI
    Summary
    CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-29 14:00 UTC
    CWE
    • n/a
    • CWE-476 - NULL Pointer Dereference
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T22:02:51.320Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=14637\u0026token=8dbd75ae7553ae3be25e22f741db783b31e14799\u0026download="
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.codesys.com/security/security-reports.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2021-29241",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-29T14:00:14.506011Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-476",
                    "description": "CWE-476 NULL Pointer Dereference",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-29T14:01:18.048Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS)."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-12-16T13:55:07.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://customers.codesys.com/index.php"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=14637\u0026token=8dbd75ae7553ae3be25e22f741db783b31e14799\u0026download="
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.codesys.com/security/security-reports.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2021-29241",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS)."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php",
                  "refsource": "MISC",
                  "url": "https://customers.codesys.com/index.php"
                },
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=14637\u0026token=8dbd75ae7553ae3be25e22f741db783b31e14799\u0026download=",
                  "refsource": "MISC",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=14637\u0026token=8dbd75ae7553ae3be25e22f741db783b31e14799\u0026download="
                },
                {
                  "name": "https://www.codesys.com/security/security-reports.html",
                  "refsource": "MISC",
                  "url": "https://www.codesys.com/security/security-reports.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2021-29241",
        "datePublished": "2021-05-03T13:17:03.000Z",
        "dateReserved": "2021-03-25T00:00:00.000Z",
        "dateUpdated": "2026-05-29T14:01:18.048Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2020-7052 (GCVE-0-2020-7052)

    Vulnerability from nvd – Published: 2020-01-24 19:31 – Updated: 2024-08-04 09:18
    VLAI
    Summary
    CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T09:18:02.939Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.tenable.com/security/research/tra-2020-04"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=12977\u0026token=33f948eed0c2fd69d238d9515779be337ef7592d\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-01-24T19:31:58.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.tenable.com/security/research/tra-2020-04"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=12977\u0026token=33f948eed0c2fd69d238d9515779be337ef7592d\u0026download="
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2020-7052",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://www.tenable.com/security/research/tra-2020-04",
                  "refsource": "MISC",
                  "url": "https://www.tenable.com/security/research/tra-2020-04"
                },
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=12977\u0026token=33f948eed0c2fd69d238d9515779be337ef7592d\u0026download=",
                  "refsource": "CONFIRM",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=12977\u0026token=33f948eed0c2fd69d238d9515779be337ef7592d\u0026download="
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2020-7052",
        "datePublished": "2020-01-24T19:31:59.000Z",
        "dateReserved": "2020-01-14T00:00:00.000Z",
        "dateUpdated": "2024-08-04T09:18:02.939Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2026-76992 (GCVE-0-2026-76992)

    Vulnerability from cvelistv5 – Published: 2026-09-30 11:07 – Updated: 2026-09-30 15:28
    VLAI
    Title
    Uncontrolled Memory Allocation in CODESYS Gateway Client
    Summary
    The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 14:48 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    References
    Impacted products
    Vendor Product Version
    CODESYS Development System 3 Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS Gateway Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS Edge Gateway for Windows Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS HMI (SL) Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS OPC DA Server SL Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS PLCHandler Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS Runtime Toolkit Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS Edge Gateway for Linux Affected: 3.15.0.0 , < 4.23.0.0 (generic)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-76992",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T14:48:15.816736Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T15:28:07.834Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Development System 3",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Edge Gateway for Windows",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "HMI (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "OPC DA Server SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "PLCHandler",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Runtime Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Edge Gateway for Linux",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "4.23.0.0",
                  "status": "affected",
                  "version": "3.15.0.0",
                  "versionType": "generic"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_development_system_3:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_gateway:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_edge_gateway_for_windows:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_hmi_sl:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_opc_da_server_sl:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_plchandler:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_runtime_toolkit:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_edge_gateway_for_linux:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "4.23.0.0",
                      "versionStartIncluding": "3.15.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Delta Electronics Inc."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.\u003c/p\u003e"
                }
              ],
              "value": "The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T11:07:45.751Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-094/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-094",
            "defect": [
              "CERT@VDE#642222"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Uncontrolled Memory Allocation in CODESYS Gateway Client",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-76992",
        "datePublished": "2026-09-30T11:07:45.751Z",
        "dateReserved": "2026-08-20T06:57:08.465Z",
        "dateUpdated": "2026-09-30T15:28:07.834Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-5751 (GCVE-0-2023-5751)

    Vulnerability from cvelistv5 – Published: 2024-06-04 08:54 – Updated: 2024-08-02 08:07
    VLAI
    Title
    CODESYS: Development system prone to DoS through exposure of resource to wrong sphere
    Summary
    A local attacker with low privileges can read and modify any users files and cause a DoS in the working directory of the affected products due to exposure of resource to wrong sphere.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-04 14:51 UTC
    CWE
    • CWE-668 - Exposure of Resource to Wrong Sphere
    Impacted products
    Vendor Product Version
    CODESYS CODESYS Control Win (SL) Affected: 0 , < 3.5.20.10 (semver)
    Create a notification for this product.
    CODESYS CODESYS Development System V3 Affected: 0 , < 3.5.20.10 (semver)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Windows Affected: 0 , < 3.5.20.10 (semver)
    Create a notification for this product.
    CODESYS CODESYS Gateway for Windows Affected: 0 , < 3.5.20.10 (semver)
    Create a notification for this product.
    CODESYS CODESYS HMI (SL) Affected: 0 , < 3.5.20.10 (semver)
    Create a notification for this product.
    codesys control_win_sl Affected: 0 , < 3.5.20.10 (custom)
        cpe:2.3:a:codesys:control_win_sl:0:*:*:*:*:*:*:*
    Create a notification for this product.
    codesys development_system_v3 Affected: 0 , < 3.5.20.10 (custom)
        cpe:2.3:a:codesys:development_system_v3:0:*:*:*:*:*:*:*
    Create a notification for this product.
    codesys edge_gateway Affected: 0 , < 3.5.20.10 (custom)
        cpe:2.3:a:codesys:edge_gateway:0:*:*:*:*:*:*:*
    Create a notification for this product.
    codesys gateway Affected: 0 , < 3.5.20.10 (custom)
        cpe:2.3:a:codesys:gateway:0:*:*:*:*:*:*:*
    Create a notification for this product.
    codesys hmi_sl Affected: 0 , < 3.5.20.10 (custom)
        cpe:2.3:a:codesys:hmi_sl:0:*:*:*:*:*:*:*
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:codesys:control_win_sl:0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "control_win_sl",
                "vendor": "codesys",
                "versions": [
                  {
                    "lessThan": "3.5.20.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:codesys:development_system_v3:0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "development_system_v3",
                "vendor": "codesys",
                "versions": [
                  {
                    "lessThan": "3.5.20.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:codesys:edge_gateway:0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "edge_gateway",
                "vendor": "codesys",
                "versions": [
                  {
                    "lessThan": "3.5.20.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:codesys:gateway:0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "gateway",
                "vendor": "codesys",
                "versions": [
                  {
                    "lessThan": "3.5.20.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:codesys:hmi_sl:0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "hmi_sl",
                "vendor": "codesys",
                "versions": [
                  {
                    "lessThan": "3.5.20.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-5751",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-04T14:51:51.731368Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-04T17:28:31.539Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T08:07:32.848Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert.vde.com/en/advisories/VDE-2024-027"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=18354\u0026token=f3e92a942c3a2f90c272a5ded7598c6a0b5f4924\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Control Win (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.20.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Development System V3",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.20.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Edge Gateway for Windows",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.20.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Gateway for Windows",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.20.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS HMI (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.20.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "joker63"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A local attacker with low privileges can read and modify any users files and cause a DoS in the working directory of the affected products due to exposure of resource to wrong sphere.\u0026nbsp;\u003cbr\u003e"
                }
              ],
              "value": "A local attacker with low privileges can read and modify any users files and cause a DoS in the working directory of the affected products due to exposure of resource to wrong sphere.\u00a0\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-668",
                  "description": "CWE-668 Exposure of Resource to Wrong Sphere",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-04T08:54:22.046Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://cert.vde.com/en/advisories/VDE-2024-027"
            },
            {
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=18354\u0026token=f3e92a942c3a2f90c272a5ded7598c6a0b5f4924\u0026download="
            }
          ],
          "source": {
            "advisory": "VDE-2024-027",
            "defect": [
              "CERT@VDE#64603"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "CODESYS: Development system prone to DoS through exposure of resource to wrong sphere",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2023-5751",
        "datePublished": "2024-06-04T08:54:22.046Z",
        "dateReserved": "2023-10-24T11:46:25.505Z",
        "dateUpdated": "2024-08-02T08:07:32.848Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-30792 (GCVE-0-2022-30792)

    Vulnerability from cvelistv5 – Published: 2022-07-11 10:40 – Updated: 2024-09-16 23:05
    VLAI
    Title
    CODESYS: CmpChannelServer, CmpChannelServerEmbedded allow unauthenticated attackers to block all their available communication channels
    Summary
    In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected.
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    References
    Impacted products
    Vendor Product Version
    CODESYS CODESYS Control RTE (SL) Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control RTE (for Beckhoff CX) SL Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control Win (SL) Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Gateway Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Windows Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS HMI (SL) Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Development System V3 Affected: V3 , < V3.5.18.10 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control Runtime System Toolkit Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Embedded Target Visu Toolkit Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Remote Target Visu Toolkit Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for BeagleBone SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Beckhoff CX9020 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for emPC-A/iMX6 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for IOT2000 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Linux SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PFC100 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PFC200 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PLCnext SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Raspberry Pi SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for WAGO Touch Panels 600 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Linux Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    Date Public
    2022-07-08 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T07:03:38.599Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17128\u0026token=bee4d8a57f19be289d623ec90135493b5f9179e3\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CODESYS Control RTE (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control RTE (for Beckhoff CX) SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control Win (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Gateway",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Edge Gateway for Windows",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS HMI (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Development System V3",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.10",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control Runtime System Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Embedded Target Visu Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Remote Target Visu Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for BeagleBone SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Beckhoff CX9020 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for emPC-A/iMX6 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for IOT2000 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Linux SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PFC100 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PFC200 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PLCnext SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Raspberry Pi SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for WAGO Touch Panels 600 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Edge Gateway for Linux",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-07-08T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "CWE-400 Uncontrolled Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-07-11T10:40:43.000Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17128\u0026token=bee4d8a57f19be289d623ec90135493b5f9179e3\u0026download="
            }
          ],
          "source": {
            "defect": [
              "CERT@VDE#",
              "64130"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "CODESYS: CmpChannelServer, CmpChannelServerEmbedded allow unauthenticated attackers to block all their available communication channels",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "info@cert.vde.com",
              "DATE_PUBLIC": "2022-07-08T06:00:00.000Z",
              "ID": "CVE-2022-30792",
              "STATE": "PUBLIC",
              "TITLE": "CODESYS: CmpChannelServer, CmpChannelServerEmbedded allow unauthenticated attackers to block all their available communication channels"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CODESYS Control RTE (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control RTE (for Beckhoff CX) SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control Win (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Gateway",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS HMI (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Development System V3",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.10"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control Runtime System Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Embedded Target Visu Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Remote Target Visu Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for BeagleBone SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Beckhoff CX9020 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for emPC-A/iMX6 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for IOT2000 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Linux SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PFC100 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PFC200 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PLCnext SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Raspberry Pi SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for WAGO Touch Panels 600 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Linux",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "CODESYS"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-400 Uncontrolled Resource Consumption"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17128\u0026token=bee4d8a57f19be289d623ec90135493b5f9179e3\u0026download=",
                  "refsource": "CONFIRM",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17128\u0026token=bee4d8a57f19be289d623ec90135493b5f9179e3\u0026download="
                }
              ]
            },
            "source": {
              "defect": [
                "CERT@VDE#",
                "64130"
              ],
              "discovery": "UNKNOWN"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2022-30792",
        "datePublished": "2022-07-11T10:40:43.935Z",
        "dateReserved": "2022-05-16T00:00:00.000Z",
        "dateUpdated": "2024-09-16T23:05:31.037Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-30791 (GCVE-0-2022-30791)

    Vulnerability from cvelistv5 – Published: 2022-07-11 10:40 – Updated: 2024-09-16 16:48
    VLAI
    Title
    CODESYS V3: CmpBlkDrvTcp allows unauthenticated attackers to block all its available TCP connections
    Summary
    In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected.
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    References
    Impacted products
    Vendor Product Version
    CODESYS CODESYS Control RTE (SL) Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control RTE (for Beckhoff CX) SL Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control Win (SL) Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Gateway Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Windows Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS HMI (SL) Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Development System V3 Affected: V3 , < V3.5.18.10 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control Runtime System Toolkit Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Embedded Target Visu Toolkit Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Remote Target Visu Toolkit Affected: V3 , < V3.5.18.20 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for BeagleBone SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Beckhoff CX9020 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for emPC-A/iMX6 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for IOT2000 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Linux SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PFC100 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PFC200 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PLCnext SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Raspberry Pi SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for WAGO Touch Panels 600 SL Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Linux Affected: V3 , < V4.5.0.0 (custom)
    Create a notification for this product.
    Date Public
    2022-07-08 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T07:03:38.611Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17128\u0026token=bee4d8a57f19be289d623ec90135493b5f9179e3\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CODESYS Control RTE (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control RTE (for Beckhoff CX) SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control Win (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Gateway",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Edge Gateway for Windows",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS HMI (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Development System V3",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.10",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control Runtime System Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Embedded Target Visu Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Remote Target Visu Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.20",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for BeagleBone SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Beckhoff CX9020 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for emPC-A/iMX6 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for IOT2000 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Linux SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PFC100 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PFC200 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PLCnext SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Raspberry Pi SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for WAGO Touch Panels 600 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Edge Gateway for Linux",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-07-08T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "CWE-400 Uncontrolled Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-07-11T10:40:38.000Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17128\u0026token=bee4d8a57f19be289d623ec90135493b5f9179e3\u0026download="
            }
          ],
          "source": {
            "defect": [
              "CERT@VDE#",
              "64129"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "CODESYS V3: CmpBlkDrvTcp allows unauthenticated attackers to block all its available TCP connections",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "info@cert.vde.com",
              "DATE_PUBLIC": "2022-07-08T06:00:00.000Z",
              "ID": "CVE-2022-30791",
              "STATE": "PUBLIC",
              "TITLE": "CODESYS V3: CmpBlkDrvTcp allows unauthenticated attackers to block all its available TCP connections"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CODESYS Control RTE (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control RTE (for Beckhoff CX) SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control Win (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Gateway",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS HMI (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Development System V3",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.10"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control Runtime System Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Embedded Target Visu Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Remote Target Visu Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for BeagleBone SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Beckhoff CX9020 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for emPC-A/iMX6 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for IOT2000 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Linux SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PFC100 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PFC200 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PLCnext SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Raspberry Pi SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for WAGO Touch Panels 600 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Linux",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "CODESYS"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-400 Uncontrolled Resource Consumption"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17128\u0026token=bee4d8a57f19be289d623ec90135493b5f9179e3\u0026download=",
                  "refsource": "CONFIRM",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17128\u0026token=bee4d8a57f19be289d623ec90135493b5f9179e3\u0026download="
                }
              ]
            },
            "source": {
              "defect": [
                "CERT@VDE#",
                "64129"
              ],
              "discovery": "UNKNOWN"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2022-30791",
        "datePublished": "2022-07-11T10:40:38.913Z",
        "dateReserved": "2022-05-16T00:00:00.000Z",
        "dateUpdated": "2024-09-16T16:48:31.565Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-31805 (GCVE-0-2022-31805)

    Vulnerability from cvelistv5 – Published: 2022-06-24 07:46 – Updated: 2024-09-16 18:55
    VLAI
    Title
    Insecure transmission of credentials
    Summary
    In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
    CWE
    • CWE-523 - Unprotected Transport of Credentials
    References
    Date Public
    2022-06-22 22:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T07:26:01.086Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17140\u0026token=6aa2c5c4a8b83b8b09936fefed5b0b11f9d2cc6c\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Development System",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V2.3.9.69",
                  "status": "affected",
                  "version": "V2",
                  "versionType": "custom"
                },
                {
                  "lessThan": "V3.5.18.30",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Gateway Client",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V2.3.9.38",
                  "status": "affected",
                  "version": "V2",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Gateway Server",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V2.3.9.38",
                  "status": "affected",
                  "version": "V2",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Web server",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V1.1.9.23",
                  "status": "affected",
                  "version": "V1",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS SP Realtime NT",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V2.3.7.30",
                  "status": "affected",
                  "version": "V2",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS PLCWinNT",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V2.4.7.57",
                  "status": "affected",
                  "version": "V2",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Runtime Toolkit 32 bit full",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V2.4.7.57",
                  "status": "affected",
                  "version": "V2",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Edge Gateway for Windows",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.30",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS HMI (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.30",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS OPC DA Server SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.30",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS PLCHandler",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.30",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CODESYS Gateway",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.30",
                  "status": "affected",
                  "version": "V3",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-06-22T22:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIn the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.\u003c/p\u003e"
                }
              ],
              "value": "In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-523",
                  "description": "CWE-523 Unprotected Transport of Credentials",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-05-09T12:54:39.506Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17140\u0026token=6aa2c5c4a8b83b8b09936fefed5b0b11f9d2cc6c\u0026download="
            }
          ],
          "source": {
            "defect": [
              "CERT@VDE#",
              "64140"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Insecure transmission of credentials",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "info@cert.vde.com",
              "DATE_PUBLIC": "2022-06-23T10:00:00.000Z",
              "ID": "CVE-2022-31805",
              "STATE": "PUBLIC",
              "TITLE": "Insecure transmission of credentials"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CODESYS Development System",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V2",
                                "version_value": "V2.3.9.69"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Gateway Client",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V2",
                                "version_value": "V2.3.9.38"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Gateway Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V2",
                                "version_value": "V2.3.9.38"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Web server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V1",
                                "version_value": "V1.1.9.23"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS SP Realtime NT",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V2",
                                "version_value": "V2.3.7.30"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS PLCWinNT",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V2",
                                "version_value": "V2.4.7.57"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Runtime Toolkit 32 bit full",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V2",
                                "version_value": "V2.4.7.57"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS HMI (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS OPC DA Server SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS PLCHandler",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Gateway",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3",
                                "version_value": "V3.5.18.20"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "CODESYS"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-523 Unprotected Transport of Credentials"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17140\u0026token=6aa2c5c4a8b83b8b09936fefed5b0b11f9d2cc6c\u0026download=",
                  "refsource": "CONFIRM",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17140\u0026token=6aa2c5c4a8b83b8b09936fefed5b0b11f9d2cc6c\u0026download="
                }
              ]
            },
            "source": {
              "defect": [
                "CERT@VDE#",
                "64140"
              ],
              "discovery": "UNKNOWN"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2022-31805",
        "datePublished": "2022-06-24T07:46:15.076Z",
        "dateReserved": "2022-05-30T00:00:00.000Z",
        "dateUpdated": "2024-09-16T18:55:26.939Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-31804 (GCVE-0-2022-31804)

    Vulnerability from cvelistv5 – Published: 2022-06-24 07:46 – Updated: 2024-09-16 20:16
    VLAI
    Title
    CODESYS Gateway server prone to denial of service attack due to excessive memory allocation
    Summary
    The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated attacker may allocate an arbitrary amount of memory, which may lead to a crash of the Gateway due to an out-of-memory condition.
    CWE
    • CWE-789 - Memory Allocation with Excessive Size Value
    References
    Impacted products
    Vendor Product Version
    CODESYS CODESYS Gateway Server V2 Affected: unspecified , < V2.3.9.38 (custom)
    Create a notification for this product.
    Date Public
    2022-06-09 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T07:26:01.284Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CODESYS Gateway Server V2",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V2.3.9.38",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-06-09T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated attacker may allocate an arbitrary amount of memory, which may lead to a crash of the Gateway due to an out-of-memory condition."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-789",
                  "description": "CWE-789: Memory Allocation with Excessive Size Value",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-06-24T07:46:12.000Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download="
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CODESYS Gateway server prone to denial of service attack due to excessive memory allocation",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "info@cert.vde.com",
              "DATE_PUBLIC": "2022-06-09T08:02:00.000Z",
              "ID": "CVE-2022-31804",
              "STATE": "PUBLIC",
              "TITLE": "CODESYS Gateway server prone to denial of service attack due to excessive memory allocation"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CODESYS Gateway Server V2",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "V2.3.9.38"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "CODESYS"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated attacker may allocate an arbitrary amount of memory, which may lead to a crash of the Gateway due to an out-of-memory condition."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-789: Memory Allocation with Excessive Size Value"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download=",
                  "refsource": "CONFIRM",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download="
                }
              ]
            },
            "source": {
              "discovery": "UNKNOWN"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2022-31804",
        "datePublished": "2022-06-24T07:46:13.080Z",
        "dateReserved": "2022-05-30T00:00:00.000Z",
        "dateUpdated": "2024-09-16T20:16:34.660Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-31803 (GCVE-0-2022-31803)

    Vulnerability from cvelistv5 – Published: 2022-06-24 07:46 – Updated: 2024-09-16 20:01
    VLAI
    Title
    CODESYS Gateway Server V2 prone to Denial of Service Attack
    Summary
    In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all available TCP connections and prevent legitimate users or clients from establishing a new connection to the CODESYS Gateway Server V2. Existing connections are not affected and therefore remain intact.
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    References
    Impacted products
    Vendor Product Version
    CODESYS CODESYS Gateway Server V2 Affected: V2 , < V2.3.9.38 (custom)
    Create a notification for this product.
    Date Public
    2022-06-09 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T07:26:01.247Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CODESYS Gateway Server V2",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V2.3.9.38",
                  "status": "affected",
                  "version": "V2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-06-09T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all available TCP connections and prevent legitimate users or clients from establishing a new connection to the CODESYS Gateway Server V2. Existing connections are not affected and therefore remain intact."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "CWE-400 Uncontrolled Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-06-24T07:46:11.000Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download="
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CODESYS Gateway Server V2 prone to Denial of Service Attack",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "info@cert.vde.com",
              "DATE_PUBLIC": "2022-06-09T07:54:00.000Z",
              "ID": "CVE-2022-31803",
              "STATE": "PUBLIC",
              "TITLE": "CODESYS Gateway Server V2 prone to Denial of Service Attack"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CODESYS Gateway Server V2",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V2",
                                "version_value": "V2.3.9.38"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "CODESYS"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all available TCP connections and prevent legitimate users or clients from establishing a new connection to the CODESYS Gateway Server V2. Existing connections are not affected and therefore remain intact."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-400 Uncontrolled Resource Consumption"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download=",
                  "refsource": "CONFIRM",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download="
                }
              ]
            },
            "source": {
              "discovery": "UNKNOWN"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2022-31803",
        "datePublished": "2022-06-24T07:46:11.188Z",
        "dateReserved": "2022-05-30T00:00:00.000Z",
        "dateUpdated": "2024-09-16T20:01:21.315Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-31802 (GCVE-0-2022-31802)

    Vulnerability from cvelistv5 – Published: 2022-06-24 07:46 – Updated: 2024-09-17 00:32
    VLAI
    Title
    Partial string comparison in CODESYS gateway server
    Summary
    In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer real CODESYS Gateway password.
    CWE
    • CWE-187 - Partial String Comparison
    References
    Impacted products
    Vendor Product Version
    CODESYS CODESYS Gateway Server V2 Affected: V2 , < V2.3.9.38 (custom)
    Create a notification for this product.
    Date Public
    2022-06-09 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T07:26:01.284Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CODESYS Gateway Server V2",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V2.3.9.38",
                  "status": "affected",
                  "version": "V2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-06-09T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer real CODESYS Gateway password."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-187",
                  "description": "CWE-187 Partial String Comparison",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-06-24T07:46:09.000Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download="
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Partial string comparison in CODESYS gateway server",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "info@cert.vde.com",
              "DATE_PUBLIC": "2022-06-09T07:38:00.000Z",
              "ID": "CVE-2022-31802",
              "STATE": "PUBLIC",
              "TITLE": "Partial string comparison in CODESYS gateway server"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CODESYS Gateway Server V2",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V2",
                                "version_value": "V2.3.9.38"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "CODESYS"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer real CODESYS Gateway password."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-187 Partial String Comparison"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download=",
                  "refsource": "CONFIRM",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17141\u0026token=17867e35cfd30c77ba0137f9a17b3a557a4b7b66\u0026download="
                }
              ]
            },
            "source": {
              "discovery": "UNKNOWN"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2022-31802",
        "datePublished": "2022-06-24T07:46:09.625Z",
        "dateReserved": "2022-05-30T00:00:00.000Z",
        "dateUpdated": "2024-09-17T00:32:18.904Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-22517 (GCVE-0-2022-22517)

    Vulnerability from cvelistv5 – Published: 2022-04-07 18:21 – Updated: 2024-09-16 22:16
    VLAI
    Title
    Communication Components in multiple CODESYS products vulnerable to communication channel disruption
    Summary
    An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.
    CWE
    • CWE-334 - Small Space of Random Values
    References
    Impacted products
    Vendor Product Version
    CODESYS CODESYS Control RTE (SL) Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control RTE (for Beckhoff CX) SL Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control Win (SL) Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Gateway Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Windows Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS HMI (SL) Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Development System V3 Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control Runtime System Toolkit Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Embedded Target Visu Toolkit Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Remote Target Visu Toolkit Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for BeagleBone SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Beckhoff CX9020 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for emPC-A/iMX6 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for IOT2000 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Linux SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PFC100 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PFC200 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PLCnext SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Raspberry Pi SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for WAGO Touch Panels 600 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Linux Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS OPC DA Server SL Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS PLCHandler Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    Date Public
    2022-04-06 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T03:14:55.454Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17091\u0026token=c450f8bbbd838c647d102f359356386c6ea5aeca\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CODESYS Control RTE (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control RTE (for Beckhoff CX) SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control Win (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Gateway",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Edge Gateway for Windows",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS HMI (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Development System V3",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control Runtime System Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Embedded Target Visu Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Remote Target Visu Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for BeagleBone SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Beckhoff CX9020 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for emPC-A/iMX6 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for IOT2000 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Linux SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PFC100 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PFC200 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PLCnext SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Raspberry Pi SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for WAGO Touch Panels 600 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Edge Gateway for Linux",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS OPC DA Server SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS PLCHandler",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-04-06T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-334",
                  "description": "CWE-334 Small Space of Random Values",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-04-07T18:21:19.000Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17091\u0026token=c450f8bbbd838c647d102f359356386c6ea5aeca\u0026download="
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Communication Components in multiple CODESYS products vulnerable to communication channel disruption",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "info@cert.vde.com",
              "DATE_PUBLIC": "2022-04-06T10:00:00.000Z",
              "ID": "CVE-2022-22517",
              "STATE": "PUBLIC",
              "TITLE": "Communication Components in multiple CODESYS products vulnerable to communication channel disruption"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CODESYS Control RTE (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control RTE (for Beckhoff CX) SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control Win (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Gateway",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS HMI (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Development System V3",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control Runtime System Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Embedded Target Visu Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Remote Target Visu Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for BeagleBone SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Beckhoff CX9020 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for emPC-A/iMX6 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for IOT2000 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Linux SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PFC100 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PFC200 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PLCnext SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Raspberry Pi SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for WAGO Touch Panels 600 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Linux",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS OPC DA Server SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS PLCHandler",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "CODESYS"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-334 Small Space of Random Values"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17091\u0026token=c450f8bbbd838c647d102f359356386c6ea5aeca\u0026download=",
                  "refsource": "MISC",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17091\u0026token=c450f8bbbd838c647d102f359356386c6ea5aeca\u0026download="
                }
              ]
            },
            "source": {
              "discovery": "UNKNOWN"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2022-22517",
        "datePublished": "2022-04-07T18:21:20.091Z",
        "dateReserved": "2022-01-03T00:00:00.000Z",
        "dateUpdated": "2024-09-16T22:16:04.923Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-22514 (GCVE-0-2022-22514)

    Vulnerability from cvelistv5 – Published: 2022-04-07 18:21 – Updated: 2024-09-17 03:03
    VLAI
    Title
    Untrusted Pointer Dereference in multiple CODESYS products can lead to a DoS.
    Summary
    An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed, this results in a crash.
    CWE
    • CWE-822 - Untrusted Pointer Dereference
    References
    Impacted products
    Vendor Product Version
    CODESYS CODESYS Control RTE (SL) Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control RTE (for Beckhoff CX) SL Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control Win (SL) Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Gateway Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Windows Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS HMI (SL) Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Development System V3 Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control Runtime System Toolkit Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Embedded Target Visu Toolkit Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Remote Target Visu Toolkit Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for BeagleBone SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Beckhoff CX9020 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for emPC-A/iMX6 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for IOT2000 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Linux SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PFC100 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PFC200 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PLCnext SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Raspberry Pi SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for WAGO Touch Panels 600 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Linux Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    Date Public
    2022-04-06 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T03:14:55.446Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17093\u0026token=15cd8424832ea10dcd4873a409a09a539ee381ca\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CODESYS Control RTE (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control RTE (for Beckhoff CX) SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control Win (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Gateway",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Edge Gateway for Windows",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS HMI (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Development System V3",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control Runtime System Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Embedded Target Visu Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Remote Target Visu Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for BeagleBone SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Beckhoff CX9020 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for emPC-A/iMX6 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for IOT2000 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Linux SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PFC100 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PFC200 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PLCnext SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Raspberry Pi SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for WAGO Touch Panels 600 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Edge Gateway for Linux",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-04-06T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed, this results in a crash."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-822",
                  "description": "CWE-822: Untrusted Pointer Dereference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-04-27T05:55:11.000Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17093\u0026token=15cd8424832ea10dcd4873a409a09a539ee381ca\u0026download="
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Untrusted Pointer Dereference in multiple CODESYS products can lead to a DoS.",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "info@cert.vde.com",
              "DATE_PUBLIC": "2022-04-06T10:00:00.000Z",
              "ID": "CVE-2022-22514",
              "STATE": "PUBLIC",
              "TITLE": "Untrusted Pointer Dereference in multiple CODESYS products can lead to a DoS."
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CODESYS Control RTE (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control RTE (for Beckhoff CX) SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control Win (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Gateway",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS HMI (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Development System V3",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control Runtime System Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Embedded Target Visu Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Remote Target Visu Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for BeagleBone SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Beckhoff CX9020 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for emPC-A/iMX6 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for IOT2000 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Linux SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PFC100 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PFC200 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PLCnext SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Raspberry Pi SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for WAGO Touch Panels 600 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Linux",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "CODESYS"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed, this results in a crash."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-822: Untrusted Pointer Dereference"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17093\u0026token=15cd8424832ea10dcd4873a409a09a539ee381ca\u0026download=",
                  "refsource": "MISC",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17093\u0026token=15cd8424832ea10dcd4873a409a09a539ee381ca\u0026download="
                }
              ]
            },
            "source": {
              "discovery": "UNKNOWN"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2022-22514",
        "datePublished": "2022-04-07T18:21:14.309Z",
        "dateReserved": "2022-01-03T00:00:00.000Z",
        "dateUpdated": "2024-09-17T03:03:50.086Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-22513 (GCVE-0-2022-22513)

    Vulnerability from cvelistv5 – Published: 2022-04-07 18:21 – Updated: 2024-09-17 04:29
    VLAI
    Title
    Null Pointer Dereference in multiple CODESYS products can lead to a DoS.
    Summary
    An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.
    CWE
    • CWE-476 - NULL Pointer Dereference
    References
    Impacted products
    Vendor Product Version
    CODESYS CODESYS Control RTE (SL) Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control RTE (for Beckhoff CX) SL Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control Win (SL) Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Gateway Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Windows Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS HMI (SL) Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Development System V3 Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control Runtime System Toolkit Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Embedded Target Visu Toolkit Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Remote Target Visu Toolkit Affected: V3.5.18.0 , < V3.5.18.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for BeagleBone SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Beckhoff CX9020 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for emPC-A/iMX6 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for IOT2000 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Linux SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PFC100 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PFC200 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for PLCnext SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for Raspberry Pi SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Control for WAGO Touch Panels 600 SL Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    CODESYS CODESYS Edge Gateway for Linux Affected: V4.5.0.0 , < V4.5.0.0 (custom)
    Create a notification for this product.
    Date Public
    2022-04-06 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T03:14:55.460Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17093\u0026token=15cd8424832ea10dcd4873a409a09a539ee381ca\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CODESYS Control RTE (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control RTE (for Beckhoff CX) SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control Win (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Gateway",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Edge Gateway for Windows",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS HMI (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Development System V3",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control Runtime System Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Embedded Target Visu Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Remote Target Visu Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V3.5.18.0",
                  "status": "affected",
                  "version": "V3.5.18.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for BeagleBone SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Beckhoff CX9020 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for emPC-A/iMX6 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for IOT2000 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Linux SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PFC100 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PFC200 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for PLCnext SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for Raspberry Pi SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Control for WAGO Touch Panels 600 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "CODESYS Edge Gateway for Linux",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "V4.5.0.0",
                  "status": "affected",
                  "version": "V4.5.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-04-06T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-476",
                  "description": "CWE-476 NULL Pointer Dereference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-04-27T05:55:10.000Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17093\u0026token=15cd8424832ea10dcd4873a409a09a539ee381ca\u0026download="
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Null Pointer Dereference in multiple CODESYS products can lead to a DoS.",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "info@cert.vde.com",
              "DATE_PUBLIC": "2022-04-06T10:00:00.000Z",
              "ID": "CVE-2022-22513",
              "STATE": "PUBLIC",
              "TITLE": "Null Pointer Dereference in multiple CODESYS products can lead to a DoS."
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CODESYS Control RTE (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control RTE (for Beckhoff CX) SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control Win (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Gateway",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS HMI (SL)",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Development System V3",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control Runtime System Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Embedded Target Visu Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Remote Target Visu Toolkit",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V3.5.18.0",
                                "version_value": "V3.5.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for BeagleBone SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Beckhoff CX9020 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for emPC-A/iMX6 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for IOT2000 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Linux SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PFC100 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PFC200 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for PLCnext SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for Raspberry Pi SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Control for WAGO Touch Panels 600 SL",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CODESYS Edge Gateway for Linux",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "V4.5.0.0",
                                "version_value": "V4.5.0.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "CODESYS"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-476 NULL Pointer Dereference"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17093\u0026token=15cd8424832ea10dcd4873a409a09a539ee381ca\u0026download=",
                  "refsource": "MISC",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17093\u0026token=15cd8424832ea10dcd4873a409a09a539ee381ca\u0026download="
                }
              ]
            },
            "source": {
              "discovery": "UNKNOWN"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2022-22513",
        "datePublished": "2022-04-07T18:21:12.792Z",
        "dateReserved": "2022-01-03T00:00:00.000Z",
        "dateUpdated": "2024-09-17T04:29:14.122Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-36764 (GCVE-0-2021-36764)

    Vulnerability from cvelistv5 – Published: 2021-08-04 13:35 – Updated: 2024-08-04 01:01
    VLAI
    Summary
    In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products and may result in a denial-of-service condition.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T01:01:59.256Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=16804\u0026token=d8c89c887979b22fdfc9fd5c3aa3804bbb1ddbff\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products and may result in a denial-of-service condition."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-08-04T13:35:31.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=16804\u0026token=d8c89c887979b22fdfc9fd5c3aa3804bbb1ddbff\u0026download="
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2021-36764",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products and may result in a denial-of-service condition."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=16804\u0026token=d8c89c887979b22fdfc9fd5c3aa3804bbb1ddbff\u0026download=",
                  "refsource": "CONFIRM",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=16804\u0026token=d8c89c887979b22fdfc9fd5c3aa3804bbb1ddbff\u0026download="
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2021-36764",
        "datePublished": "2021-08-04T13:35:31.000Z",
        "dateReserved": "2021-07-16T00:00:00.000Z",
        "dateUpdated": "2024-08-04T01:01:59.256Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-29242 (GCVE-0-2021-29242)

    Vulnerability from cvelistv5 – Published: 2021-05-03 13:56 – Updated: 2024-08-03 22:02
    VLAI
    Summary
    CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.
    Severity
    No CVSS data available.
    CWE
    • n/a
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T22:02:51.582Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.codesys.com/security/security-reports.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=14640\u0026token=623b6fceb0579ef0f7505e29beefa5b3f8ac7873\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router\u0027s addressing scheme and may re-route, add, remove or change low level communication packages."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-05-03T13:56:06.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://customers.codesys.com/index.php"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.codesys.com/security/security-reports.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=14640\u0026token=623b6fceb0579ef0f7505e29beefa5b3f8ac7873\u0026download="
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2021-29242",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router\u0027s addressing scheme and may re-route, add, remove or change low level communication packages."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php",
                  "refsource": "MISC",
                  "url": "https://customers.codesys.com/index.php"
                },
                {
                  "name": "https://www.codesys.com/security/security-reports.html",
                  "refsource": "MISC",
                  "url": "https://www.codesys.com/security/security-reports.html"
                },
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=14640\u0026token=623b6fceb0579ef0f7505e29beefa5b3f8ac7873\u0026download=",
                  "refsource": "MISC",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=14640\u0026token=623b6fceb0579ef0f7505e29beefa5b3f8ac7873\u0026download="
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2021-29242",
        "datePublished": "2021-05-03T13:56:06.000Z",
        "dateReserved": "2021-03-25T00:00:00.000Z",
        "dateUpdated": "2024-08-03T22:02:51.582Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-29241 (GCVE-0-2021-29241)

    Vulnerability from cvelistv5 – Published: 2021-05-03 13:17 – Updated: 2026-05-29 14:01
    VLAI
    Summary
    CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-29 14:00 UTC
    CWE
    • n/a
    • CWE-476 - NULL Pointer Dereference
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T22:02:51.320Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=14637\u0026token=8dbd75ae7553ae3be25e22f741db783b31e14799\u0026download="
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.codesys.com/security/security-reports.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2021-29241",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-29T14:00:14.506011Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-476",
                    "description": "CWE-476 NULL Pointer Dereference",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-29T14:01:18.048Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS)."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-12-16T13:55:07.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://customers.codesys.com/index.php"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=14637\u0026token=8dbd75ae7553ae3be25e22f741db783b31e14799\u0026download="
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.codesys.com/security/security-reports.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2021-29241",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS)."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://customers.codesys.com/index.php",
                  "refsource": "MISC",
                  "url": "https://customers.codesys.com/index.php"
                },
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=14637\u0026token=8dbd75ae7553ae3be25e22f741db783b31e14799\u0026download=",
                  "refsource": "MISC",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=14637\u0026token=8dbd75ae7553ae3be25e22f741db783b31e14799\u0026download="
                },
                {
                  "name": "https://www.codesys.com/security/security-reports.html",
                  "refsource": "MISC",
                  "url": "https://www.codesys.com/security/security-reports.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2021-29241",
        "datePublished": "2021-05-03T13:17:03.000Z",
        "dateReserved": "2021-03-25T00:00:00.000Z",
        "dateUpdated": "2026-05-29T14:01:18.048Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2020-7052 (GCVE-0-2020-7052)

    Vulnerability from cvelistv5 – Published: 2020-01-24 19:31 – Updated: 2024-08-04 09:18
    VLAI
    Summary
    CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T09:18:02.939Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.tenable.com/security/research/tra-2020-04"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=12977\u0026token=33f948eed0c2fd69d238d9515779be337ef7592d\u0026download="
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-01-24T19:31:58.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.tenable.com/security/research/tra-2020-04"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=12977\u0026token=33f948eed0c2fd69d238d9515779be337ef7592d\u0026download="
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2020-7052",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://www.tenable.com/security/research/tra-2020-04",
                  "refsource": "MISC",
                  "url": "https://www.tenable.com/security/research/tra-2020-04"
                },
                {
                  "name": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=12977\u0026token=33f948eed0c2fd69d238d9515779be337ef7592d\u0026download=",
                  "refsource": "CONFIRM",
                  "url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=12977\u0026token=33f948eed0c2fd69d238d9515779be337ef7592d\u0026download="
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2020-7052",
        "datePublished": "2020-01-24T19:31:59.000Z",
        "dateReserved": "2020-01-14T00:00:00.000Z",
        "dateUpdated": "2024-08-04T09:18:02.939Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }