CVE-2024-8175

HIGH

CODESYS - DoS

Title source: llm
STIX 2.1

Description

An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS.

Scores

CVSS v3 7.5
EPSS 0.0089
EPSS Percentile 75.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-754
Status published
Products (18)
CODESYS/CODESYS Control for BeagleBone SL < 4.14.0.0
CODESYS/CODESYS Control for emPC-A/iMX6 SL < 4.14.0.0
CODESYS/CODESYS Control for IOT2000 SL < 4.14.0.0
CODESYS/CODESYS Control for Linux ARM SL < 4.14.0.0
CODESYS/CODESYS Control for Linux SL < 4.14.0.0
CODESYS/CODESYS Control for PFC100 SL < 4.14.0.0
CODESYS/CODESYS Control for PFC200 SL < 4.14.0.0
CODESYS/CODESYS Control for PLCnext SL < 4.14.0.0
CODESYS/CODESYS Control for Raspberry Pi SL < 4.14.0.0
CODESYS/CODESYS Control for WAGO Touch Panels 600 SL < 4.14.0.0
... and 8 more
Published Sep 25, 2024
Tracked Since Feb 18, 2026