CODESYS CVE Vulnerabilities & CVE List (136)

Products (CPE): — CVEs: 136

CODESYS vulnerability overview

Aggregates CVE and security vulnerability intelligence across all CODESYS-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk memory corruption and vendor risk buffer overflow and related problems; some flaws may lead to vendor impact file overwrite, affecting vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 81100 of 136 CVEs
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2021-34595 A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite. [email protected] 8.1 0.85% 2021-10-26 2026-06-16
CVE-2021-34593 In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC. [email protected] 7.5 2.65% 2021-10-26 2026-06-16
CVE-2021-34586 In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the CODESYS web server and may result in a denial-of-service condition. [email protected] 7.5 13.08% 2021-10-26 2026-06-16
CVE-2021-34585 In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation. [email protected] 7.5 0.90% 2021-10-26 2026-06-16
CVE-2021-34584 Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22. [email protected] 9.1 1.07% 2021-10-26 2026-06-16
CVE-2021-34583 Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22. [email protected] 7.5 8.41% 2021-10-26 2026-06-16
CVE-2021-21869 An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability. [email protected] 7.8 1.77% 2021-08-25 2026-06-16
CVE-2021-21868 An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability. [email protected] 7.8 1.61% 2021-08-18 2026-06-16
CVE-2021-21867 An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability. [email protected] 7.8 1.65% 2021-08-18 2026-06-16
CVE-2021-21863 A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability. [email protected] 7.8 1.22% 2021-08-05 2026-06-16
CVE-2021-36765 In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP stack that is executed by the CODESYS Control runtime system. [email protected] 7.5 0.99% 2021-08-04 2026-06-16
CVE-2021-36764 In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products and may result in a denial-of-service condition. [email protected] 7.5 0.99% 2021-08-04 2026-06-16
CVE-2021-36763 In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties. [email protected] 7.5 1.01% 2021-08-03 2026-06-16
CVE-2021-33486 All versions of the CODESYS V3 Runtime Toolkit for VxWorks from version V3.5.8.0 and before version V3.5.17.10 have Improper Handling of Exceptional Conditions. [email protected] 7.5 0.96% 2021-08-03 2026-06-16
CVE-2021-33485 CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow. [email protected] 9.8 1.14% 2021-08-03 2026-06-16
CVE-2021-21866 A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability. [email protected] 7.8 1.67% 2021-08-02 2026-06-16
CVE-2021-21865 A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Development System 3.5.16. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability. [email protected] 7.8 1.30% 2021-08-02 2026-06-16
CVE-2021-21864 A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability. [email protected] 7.8 1.73% 2021-08-02 2026-06-16
CVE-2021-30195 CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation. [email protected] 7.5 7.18% 2021-05-25 2026-06-16
CVE-2021-30194 CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read. [email protected] 9.1 1.15% 2021-05-25 2026-06-16
cvelogic Threat Intelligence