Browse all 94 CVE security advisories affecting CODESYS. AI-powered Chinese analysis, POCs, and references for each vulnerability.
CODESYS serves as a widely adopted software development environment for industrial automation, enabling the creation of control applications for programmable logic controllers (PLCs). Its extensive use in critical infrastructure has made it a significant target for cyberattacks, resulting in 94 recorded Common Vulnerabilities and Exposures. Historically, the platform has been susceptible to remote code execution, buffer overflows, and privilege escalation flaws, often stemming from insecure default configurations or unpatched legacy components. Notable incidents include the exploitation of the CODESYS Control Win32 service, which allowed attackers to execute arbitrary commands with system-level privileges. These vulnerabilities highlight the risks associated with embedded industrial software, particularly when deployed without rigorous security hardening. The high volume of CVEs underscores the necessity for continuous patch management and secure coding practices within the industrial IoT ecosystem to mitigate potential operational disruptions.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2021-34585 | CODESYS V2 web server: crafted requests could trigger a pointer dereference with an invalid address (DoS) — CODESYS V2CWE-252 | 7.5 | High | 2021-10-26 |
| CVE-2021-34584 | CODESYS V2 web server: crafted requests could trigger a buffer over-read (DoS) — CODESYS V2CWE-126 | 9.1 | Critical | 2021-10-26 |
| CVE-2021-34583 | CODESYS V2 web server: crafted requests could trigger a heap-based buffer overflow (DoS) — CODESYS V2CWE-122 | 7.5 | High | 2021-10-26 |
| CVE-2015-6460 | CODESYS Gateway Server 缓冲区错误漏洞 — 3S-Smart CODESYS Gateway Server | 9.8 | - | 2015-09-18 |
This page lists every published CVE security advisory associated with CODESYS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.