Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

3ssoftware

First CVE: Dec 25, 2011Active for: 15 yearsTotal CVEs: 17

3ssoftware produces CODESYS, an industrial automation and control software platform widely used in programmable logic controllers and embedded systems. The vendor's vulnerability exposure centers on memory-safety boundary violations across its runtime, gateway, and web-server components, reflecting the firmware and embedded-systems context of its deployments.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 79% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
8.5
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by 3ssoftware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 25, 2011
14 years ago
Most Recent CVE
Feb 15, 2018
3,081 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2011-5007HIGH
Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, allows remote attacke
Dec 25, 201110.083NOYES
CVE-2012-4705HIGH
Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors involving a crafted pathname.
Feb 24, 201310.081NOYES
CVE-2012-6069CRITICAL
The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker to access files and directories outside the intended scope.
Jan 21, 201310.033NONO
CVE-2012-6068CRITICAL
The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in t
Jan 21, 20139.832NONO
CVE-2018-5440CRITICAL
A Stack-based Buffer Overflow issue was discovered in 3S-Smart CODESYS Web Server. Specifically: all Microsoft Windows (also WinCE) based CODESYS web servers running stand-alone Ve
Feb 15, 20189.831NONO
CVE-2012-4708HIGH
Stack-based buffer overflow in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet.
Feb 24, 201310.030NONO
CVE-2011-5009MEDIUM
The CmpWebServer.dll module in the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a crafted C
Dec 25, 20115.030NOYES
CVE-2014-0760HIGH
The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion provide an undocumented access method involving the FTP pr
Apr 25, 20149.329NONO
CVE-2012-4707HIGH
3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors that trigger an out-of-bounds memory access.
Feb 24, 201310.029NONO
CVE-2012-4704HIGH
Array index error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet.
Feb 24, 201310.028NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
24%
59%
18%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (17.6%)
Unknown14 (82.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (17.6%)
High0 (0.0%)
Unknown14 (82.4%)
User Interaction
None3 (17.6%)
Unknown14 (82.4%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (17.6%)
Unknown14 (82.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
11.8% of CVEs· 99th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
17.6% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by 3ssoftware.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by 3ssoftware — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For 3ssoftware's Products

View all 2 CNAs →

Top CWEs