
CVE-2021-34584 – CODESYS V2 web server: crafted requests could trigger a buffer over-read (DoS)
https://notcve.org/view.php?id=CVE-2021-34584
26 Oct 2021 — Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22. Unas peticiones del servidor web diseñadas pueden ser usadas para leer parcialmente la pila o la memoria de la pila o pueden desencadenar una situación de denegación de servicio debido a un bloqueo en el servidor web de CODESYS V2 versiones anteriores a 1.1.9.22 • https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=16876&token=a3f1d937f95e7034879f4f2ea8e5a99b168256a7&download= • CWE-126: Buffer Over-read •

CVE-2021-34583 – CODESYS V2 web server: crafted requests could trigger a heap-based buffer overflow (DoS)
https://notcve.org/view.php?id=CVE-2021-34583
26 Oct 2021 — Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22. Unas peticiones del servidor web diseñadas pueden causar un desbordamiento del búfer en la región heap de la memoria y, por tanto, podrían desencadenar una situación de denegación de servicio debido a un bloqueo en el servidor web de CODESYS V2 versiones anteriores a 1.1.9.22 • https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=16876&token=a3f1d937f95e7034879f4f2ea8e5a99b168256a7&download= • CWE-122: Heap-based Buffer Overflow CWE-787: Out-of-bounds Write •

CVE-2021-21869
https://notcve.org/view.php?id=CVE-2021-21869
25 Aug 2021 — An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability. Se presenta una vulnerabilidad de deserialización no segura en la funcionalidad Engine.plugin ProfileInformation ProfileData de CODESYS GmbH CODESYS Development System versiones 3.5.16 y 3.5.17. Un a... • https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=16805&token=ee583c498941d9fda86490bca98ff21928eec08a&download= • CWE-502: Deserialization of Untrusted Data •

CVE-2021-21868
https://notcve.org/view.php?id=CVE-2021-21868
18 Aug 2021 — An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability. Se presenta una vulnerabilidad de deserialización no segura en la funcionalidad ObjectManager.plugin Project.get_MissingTypes() de CODESYS GmbH CODESYS Development System versiones 3.5.16 y 3.5.17... • https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=16805&token=ee583c498941d9fda86490bca98ff21928eec08a&download= • CWE-502: Deserialization of Untrusted Data •

CVE-2021-21867
https://notcve.org/view.php?id=CVE-2021-21867
18 Aug 2021 — An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability. Se presenta una vulnerabilidad de deserialización no segura en la funcionalidad ObjectManager.plugin ObjectStream.ProfileByteArray de CODESYS GmbH CODESYS Development System versiones 3.5.16 y ... • https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=16805&token=ee583c498941d9fda86490bca98ff21928eec08a&download= • CWE-502: Deserialization of Untrusted Data •

CVE-2019-5105
https://notcve.org/view.php?id=CVE-2019-5105
26 Mar 2020 — An exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S-Smart Software Solutions CODESYS GatewayService. A specially crafted packet can cause a large memcpy, resulting in an access violation and termination of the process. An attacker can send a packet to a device running the GatewayService.exe to trigger this vulnerability. All variants of the CODESYS V3 products in all versions prior V3.5.16.10 containing the CmpRouter or CmpRouterEmbedded component are affecte... • https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=13077&token=3bfc6d1d08415a6260b96093520071f5786e7fd4&download= • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-787: Out-of-bounds Write •

CVE-2019-16265
https://notcve.org/view.php?id=CVE-2019-16265
25 Oct 2019 — CODESYS V2.3 ENI server up to V3.2.2.24 has a Buffer Overflow. El servidor CODESYS V2.3 ENI hasta la versión V3.2.2.24, presenta un desbordamiento de búfer. • https://customers.codesys.com/fileadmin/data/customers/security/2019/Advisory2019-09_LCDS-319.pdf • CWE-787: Out-of-bounds Write •

CVE-2019-13538
https://notcve.org/view.php?id=CVE-2019-13538
17 Sep 2019 — 3S-Smart Software Solutions GmbH CODESYS V3 Library Manager, all versions prior to 3.5.16.0, allows the system to display active library content without checking its validity, which may allow the contents of manipulated libraries to be displayed or executed. The issue also exists for source libraries, but 3S-Smart Software Solutions GmbH strongly recommends distributing compiled libraries only. 3S-Smart Software Solutions GmbH CODESYS versión V3 Library Manager, todas las versiones anteriores a la 3.5.16.0,... • https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=12940&token=7723e5ed99830656f487e218e73dce2de751102f • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •