Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-5105

25
FAUCET Score

CVE-2019-5105 is a memory corruption vulnerability in the Name Service Client functionality of 3S-Smart Software Solutions CODESYS GatewayService, affecting all CODESYS V3 products prior to version V3.5.16.10 that include the CmpRouter or CmpRouterEmbedded component. An unauthenticated attacker can remotely trigger a large memcpy operation with a specially crafted packet, leading to an access violation and termination of the GatewayService.exe process. This vulnerability carries a CVSS v3.1 score of 7.5 (HIGH), indicating a high severity due to its network-based attack vector, low attack complexity, and complete availability impact (denial of service). There is no user interaction required, and the vulnerability does not impact confidentiality or integrity. Currently, there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, and it is not listed in CISA's KEV catalog, suggesting it is not being actively exploited in the wild. Community discussion is minimal, with only one mention identified.

Impacted Technologies

VendorProductVersion(s)CPE
3.5.13.2CPE matchmatch criteria
cpe:2.3:a:codesys:codesys:3.5.13.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
2.15%
Probability of exploitation in next 30 days
EPSS Percentile
80.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0215 is in the 65th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (5)

amazonvendor investigatingvia llm_extracted
apollographqlvendor investigatingvia llm_extracted
dfinityvendor investigatingvia llm_extracted
fleetdmvendor investigatingvia llm_extracted
mathworksvendor investigatingvia llm_extracted

Vendor Advisories (10)

fleetdmllm-fleetdm-0cffa175819eb60fHIGH

Denial of Service in PLC Runtime affecting Rexroth IndraMotion Products

Dec 16, 2020
fleetdmllm-fleetdm-dfa6928b76ca88dbCRITICAL

Multiple Vulnerabilities in 3S CODESYS Runtime in Rexroth PRC7000

Dec 16, 2020
amazonllm-amazon-a8a30150585d5212HIGH

Denial of Service in PLC Runtime affecting Rexroth IndraMotion Products

Dec 16, 2020
amazonllm-amazon-e5068a99de6e4862CRITICAL

Multiple Vulnerabilities in 3S CODESYS Runtime in Rexroth PRC7000

Dec 16, 2020
apollographqlllm-apollographql-aa28000fa0174283HIGH

Denial of Service in PLC Runtime affecting Rexroth IndraMotion Products

Dec 16, 2020
apollographqlllm-apollographql-cd81770455aec26eCRITICAL

Multiple Vulnerabilities in 3S CODESYS Runtime in Rexroth PRC7000

Dec 16, 2020
dfinityllm-dfinity-a05cc178c91490e1HIGH

Denial of Service in PLC Runtime affecting Rexroth IndraMotion Products

Dec 16, 2020
dfinityllm-dfinity-0f95073f58c8726cCRITICAL

Multiple Vulnerabilities in 3S CODESYS Runtime in Rexroth PRC7000

Dec 16, 2020
mathworksllm-mathworks-826b7e1e0214b5c7HIGH

Denial of Service in PLC Runtime affecting Rexroth IndraMotion Products

Dec 16, 2020
mathworksllm-mathworks-ec6ff689b971de03CRITICAL

Multiple Vulnerabilities in 3S CODESYS Runtime in Rexroth PRC7000

Dec 16, 2020

References

customers.codesys.com / index.php
talosintelligence.com / vulnerability_reports/TALOS-2019-0897
ExploitThird Party Advisory