Pilz manufactures industrial safety controllers and monitoring systems, including the PMC, PAS 4000, and PMI firmware-based product lines that are deployed in operational technology environments. The vendor's vulnerability profile centers on configuration and credential-handling weaknesses—path traversal, cleartext credential storage, exposure across trust boundaries, and weak password mechanisms—that are characteristic of legacy industrial control software and reflect persistent challenges in securing embedded safety devices. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pilz over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-12069HIGH In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing | Dec 26, 2022 | 7.8 | 26 | NO | NO |
CVE-2020-12067HIGH In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password. | Dec 26, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-40977HIGH A path traversal vulnerability was discovered in Pilz PASvisu Server before 1.12.0. An unauthenticated remote attacker could use a zipped, malicious configuration file to trigger a | Nov 24, 2022 | 7.5 | 25 | NO | NO |
CVE-2018-19009HIGH Pilz PNOZmulti Configurator prior to version 10.9 allows an authenticated attacker with local access to the system containing the PNOZmulti Configurator software to view sensitive | Jan 25, 2019 | 7.8 | 25 | NO | NO |
CVE-2022-40976MEDIUM A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a zipped, malicious configuration file to trigger arbitrary fil | Nov 24, 2022 | 5.5 | 21 | NO | NO |
CVE-2019-9011MEDIUM In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), an attacker can identify valid usernames. | Dec 26, 2022 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pilz.
Media articles that mention a CVE ID that affects a product developed by Pilz — matched by CVE ID, not by vendor name.