3ssoftware produces CODESYS, an industrial automation and control software platform widely used in programmable logic controllers and embedded systems. The vendor's vulnerability exposure centers on memory-safety boundary violations across its runtime, gateway, and web-server components, reflecting the firmware and embedded-systems context of its deployments.
The number and severity of CVEs published that impact products developed by 3ssoftware over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-5007HIGH Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, allows remote attacke | Dec 25, 2011 | 10.0 | 83 | NO | YES |
CVE-2012-4705HIGH Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors involving a crafted pathname. | Feb 24, 2013 | 10.0 | 81 | NO | YES |
CVE-2012-6069CRITICAL The CoDeSys Runtime Toolkit’s file transfer functionality does not
perform input validation, which allows an attacker to access files and
directories outside the intended scope. | Jan 21, 2013 | 10.0 | 33 | NO | NO |
CVE-2012-6068CRITICAL The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in t | Jan 21, 2013 | 9.8 | 32 | NO | NO |
CVE-2018-5440CRITICAL A Stack-based Buffer Overflow issue was discovered in 3S-Smart CODESYS Web Server. Specifically: all Microsoft Windows (also WinCE) based CODESYS web servers running stand-alone Ve | Feb 15, 2018 | 9.8 | 31 | NO | NO |
CVE-2012-4708HIGH Stack-based buffer overflow in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet. | Feb 24, 2013 | 10.0 | 30 | NO | NO |
CVE-2011-5009MEDIUM The CmpWebServer.dll module in the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a crafted C | Dec 25, 2011 | 5.0 | 30 | NO | YES |
CVE-2014-0760HIGH The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1
Modular Controller with CoDeSys and SoftMotion provide an undocumented
access method involving the FTP pr | Apr 25, 2014 | 9.3 | 29 | NO | NO |
CVE-2012-4707HIGH 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors that trigger an out-of-bounds memory access. | Feb 24, 2013 | 10.0 | 29 | NO | NO |
CVE-2012-4704HIGH Array index error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet. | Feb 24, 2013 | 10.0 | 28 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 3ssoftware.
Media articles that mention a CVE ID that affects a product developed by 3ssoftware — matched by CVE ID, not by vendor name.