Skip to content
Noroxi

openplcproject records

13 published records for vendor openplcproject.

All records

13 records
  • Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on

    HighCVSS 8.8Proof of conceptEPSS 27%

    openplcproject · openplc v3 firmwareAug 3, 2021

  • A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d10248

    CriticalCVSS 9.8No exploitEPSS 2%

    openplcproject · openplc v3 firmwareSep 18, 2024

  • A buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions.

    CriticalCVSS 9.8No exploitEPSS 2%

    openplcproject · openplc v2 firmwareApr 22, 2019

  • Initialization of a resource with an insecure default in OpenPLC_V3

    CriticalCVSS 9.2No exploitEPSS 1%

    openplcproject · openplc v3 firmwareApr 9, 2026

  • Plaintext storage of a password in OpenPLC_V3

    CriticalCVSS 9.2No exploitEPSS 0%

    openplcproject · openplc v3 firmwareApr 9, 2026

  • Missing Authorization in OpenPLC_V3

    HighCVSS 8.7No exploitEPSS 0%

    openplcproject · openplc v3 firmwareApr 9, 2026

  • An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f7

    HighCVSS 7.5No exploitEPSS 1%

    openplcproject · openplc v3 firmwareSep 18, 2024

  • Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a3

    HighCVSS 7.5No exploitEPSS 1%

    openplcproject · openplc v3 firmwareSep 18, 2024

  • An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f7

    HighCVSS 7.5No exploitEPSS 1%

    openplcproject · openplc v3 firmwareSep 18, 2024

  • Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a3

    HighCVSS 7.5No exploitEPSS 1%

    openplcproject · openplc v3 firmwareSep 18, 2024

  • A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_gene

    MediumCVSS 6.5Proof of conceptEPSS 0%

    openplcproject · openplc v3 firmwareMay 13, 2026

  • CVE-2021-3351
    21Monitor

    OpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page.

    MediumCVSS 5.4No exploitEPSS 1%

    openplcproject · openplcAug 2, 2021

  • OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture.

    MediumCVSS 5.4No exploitEPSS 0%

    openplcproject · openplc v3 firmwareJun 28, 2024