Aggregates CVE and security vulnerability intelligence across all CODESYS-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk memory corruption and vendor risk buffer overflow and related problems; some flaws may lead to vendor impact file overwrite, affecting vendor surface production workloads scenarios.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2021-34595 | A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite. | [email protected] | 8.1 | 0.85% | 2021-10-26 | 2026-06-16 |
| CVE-2021-34593 | In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC. | [email protected] | 7.5 | 2.65% | 2021-10-26 | 2026-06-16 |
| CVE-2021-34586 | In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the CODESYS web server and may result in a denial-of-service condition. | [email protected] | 7.5 | 13.08% | 2021-10-26 | 2026-06-16 |
| CVE-2021-34585 | In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation. | [email protected] | 7.5 | 0.90% | 2021-10-26 | 2026-06-16 |
| CVE-2021-34584 | Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22. | [email protected] | 9.1 | 1.07% | 2021-10-26 | 2026-06-16 |
| CVE-2021-34583 | Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22. | [email protected] | 7.5 | 8.41% | 2021-10-26 | 2026-06-16 |
| CVE-2021-21869 | An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability. | [email protected] | 7.8 | 1.77% | 2021-08-25 | 2026-06-16 |
| CVE-2021-21868 | An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability. | [email protected] | 7.8 | 1.61% | 2021-08-18 | 2026-06-16 |
| CVE-2021-21867 | An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability. | [email protected] | 7.8 | 1.65% | 2021-08-18 | 2026-06-16 |
| CVE-2021-21863 | A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability. | [email protected] | 7.8 | 1.22% | 2021-08-05 | 2026-06-16 |
| CVE-2021-36765 | In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP stack that is executed by the CODESYS Control runtime system. | [email protected] | 7.5 | 0.99% | 2021-08-04 | 2026-06-16 |
| CVE-2021-36764 | In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products and may result in a denial-of-service condition. | [email protected] | 7.5 | 0.99% | 2021-08-04 | 2026-06-16 |
| CVE-2021-36763 | In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties. | [email protected] | 7.5 | 1.01% | 2021-08-03 | 2026-06-16 |
| CVE-2021-33486 | All versions of the CODESYS V3 Runtime Toolkit for VxWorks from version V3.5.8.0 and before version V3.5.17.10 have Improper Handling of Exceptional Conditions. | [email protected] | 7.5 | 0.96% | 2021-08-03 | 2026-06-16 |
| CVE-2021-33485 | CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow. | [email protected] | 9.8 | 1.14% | 2021-08-03 | 2026-06-16 |
| CVE-2021-21866 | A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability. | [email protected] | 7.8 | 1.67% | 2021-08-02 | 2026-06-16 |
| CVE-2021-21865 | A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Development System 3.5.16. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability. | [email protected] | 7.8 | 1.30% | 2021-08-02 | 2026-06-16 |
| CVE-2021-21864 | A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability. | [email protected] | 7.8 | 1.73% | 2021-08-02 | 2026-06-16 |
| CVE-2021-30195 | CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation. | [email protected] | 7.5 | 7.18% | 2021-05-25 | 2026-06-16 |
| CVE-2021-30194 | CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read. | [email protected] | 9.1 | 1.15% | 2021-05-25 | 2026-06-16 |