Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-76992 1 Codesys 15 Codesys Development System 3, Codesys Edge Gateway For Linux, Codesys Edge Gateway For Windows and 12 more 2026-09-30 7.5 High
The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.
CVE-2022-1794 2 Codesys, Microsoft 2 Opc Da Server, Windows 2024-11-21 5.5 Medium
The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is visible to all authorized Microsoft Windows users of the system.