Codesys Gateway Server

Vendor:

First CVE: Feb 24, 2013 · Active for 13 years

6
Total CVEs
More Total CVEs than 80% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
9.6
Avg CVSS
Higher Avg CVSS than 87% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Codesys Gateway Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 24, 2013
13 years ago
Most Recent CVE
May 23, 2013
4,810 days ago

CVE Severity & Scoring

Codesys Gateway Server6 CVEs
All CVEs352,294 CVEs
High
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown6 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown6 (100.0%)
User Interaction
None0 (0.0%)
Unknown6 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown6 (100.0%)

Top CVEs

Signals from CVEs in this product scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors involving a crafted pathname.
Feb 24, 201310.081NOYES
Stack-based buffer overflow in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet.
Feb 24, 201310.030NONO
3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors that trigger an out-of-bounds memory access.
Feb 24, 201310.029NONO
Array index error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet.
Feb 24, 201310.028NONO
Use-after-free vulnerability in the server application in 3S CODESYS Gateway 2.3.9.27 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitr
May 23, 201310.026NONO
Integer signedness error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to cause a denial of service via a crafted packet that triggers a heap-based buffer ov
Feb 24, 20137.822NONO

Exploit Exposure

Signals from CVEs in this product scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
16.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
16.7% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (6 CVEs).

Media Mentions

Signals from CVEs in this product scope (6 CVEs).

Top CNAs Publishing CVEs For Codesys Gateway Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.3.9.559.616.5%01
2.3.9.459.616.5%01
2.3.9.359.616.5%01
2.3.9.27110.03.8%00
2.3.9.259.616.5%01
2.3.9.1949.419.7%01
2.3.9.1859.616.5%01
2.3.9.159.616.5%01
2.3.959.616.5%01
2.3.8.259.616.5%01
2.3.8.159.616.5%01
2.3.8.059.616.5%01
2.3.7.059.616.5%01
2.3.6.059.616.5%01
2.3.5.359.616.5%01
2.3.5.259.616.5%01
2.3.5.159.616.5%01