Codesys Gateway Server
Vendor:
First CVE: Feb 24, 2013 · Active for 13 years
6
Total CVEs
More Total CVEs than 80% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
9.6
Avg CVSS
Higher Avg CVSS than 87% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Codesys Gateway Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 24, 2013
13 years ago
Most Recent CVE
May 23, 2013
4,810 days ago
CVE Severity & Scoring
Codesys Gateway Server6 CVEs
100%
All CVEs352,294 CVEs
45%
40%
11%
High
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown6 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown6 (100.0%)
User Interaction
None0 (0.0%)
Unknown6 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown6 (100.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4705HIGH Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors involving a crafted pathname. | Feb 24, 2013 | 10.0 | 81 | NO | YES |
CVE-2012-4708HIGH Stack-based buffer overflow in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet. | Feb 24, 2013 | 10.0 | 30 | NO | NO |
CVE-2012-4707HIGH 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors that trigger an out-of-bounds memory access. | Feb 24, 2013 | 10.0 | 29 | NO | NO |
CVE-2012-4704HIGH Array index error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet. | Feb 24, 2013 | 10.0 | 28 | NO | NO |
CVE-2013-2781HIGH Use-after-free vulnerability in the server application in 3S CODESYS Gateway 2.3.9.27 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitr | May 23, 2013 | 10.0 | 26 | NO | NO |
CVE-2012-4706HIGH Integer signedness error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to cause a denial of service via a crafted packet that triggers a heap-based buffer ov | Feb 24, 2013 | 7.8 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
16.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
16.7% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Codesys Gateway Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.3.9.5 | 5 | 9.6 | 16.5% | 0 | 1 |
| 2.3.9.4 | 5 | 9.6 | 16.5% | 0 | 1 |
| 2.3.9.3 | 5 | 9.6 | 16.5% | 0 | 1 |
| 2.3.9.27 | 1 | 10.0 | 3.8% | 0 | 0 |
| 2.3.9.2 | 5 | 9.6 | 16.5% | 0 | 1 |
| 2.3.9.19 | 4 | 9.4 | 19.7% | 0 | 1 |
| 2.3.9.18 | 5 | 9.6 | 16.5% | 0 | 1 |
| 2.3.9.1 | 5 | 9.6 | 16.5% | 0 | 1 |
| 2.3.9 | 5 | 9.6 | 16.5% | 0 | 1 |
| 2.3.8.2 | 5 | 9.6 | 16.5% | 0 | 1 |
| 2.3.8.1 | 5 | 9.6 | 16.5% | 0 | 1 |
| 2.3.8.0 | 5 | 9.6 | 16.5% | 0 | 1 |
| 2.3.7.0 | 5 | 9.6 | 16.5% | 0 | 1 |
| 2.3.6.0 | 5 | 9.6 | 16.5% | 0 | 1 |
| 2.3.5.3 | 5 | 9.6 | 16.5% | 0 | 1 |
| 2.3.5.2 | 5 | 9.6 | 16.5% | 0 | 1 |
| 2.3.5.1 | 5 | 9.6 | 16.5% | 0 | 1 |