← Vulnerability feed

Vulnerability record · CVE-2019-19789 · published 20 December 2019

CVE-2019-19789: Codesys plcwinnt null pointer dereference vulnerability

Codesys · Plcwinnt

3S-Smart CODESYS SP Realtime NT before V2.3.7.28, CODESYS Runtime Toolkit 32 bit full before V2.4.7.54, and CODESYS PLCWinNT before V2.4.7.54 allow a NULL pointer dereference.

6.5 CVSS 3.1 Medium EPSS 1.2% · top 32.6% CWE-476 · NULL pointer dereference
6.5CVSS 3.1 base score, v2 4.0
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

3S-Smart CODESYS SP Realtime NT before V2.3.7.28, CODESYS Runtime Toolkit 32 bit full before V2.4.7.54, and CODESYS PLCWinNT before V2.4.7.54 allow a NULL pointer dereference.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-19789 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-31806Codesys plcwinnt insecure default initialization vulnerabilityIn CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no informatio…EPSS 1.2%8.8CVE-2023-6357Codesys control for beaglebone sl os command injection vulnerabilityA low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the…EPSS 0.96%8.8CVE-2022-4224Codesys control for beaglebone sl insecure default initialization vulnerabilityIn multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files…EPSS 0.88%8.8CVE-2022-32143Codesys plcwinnt vulnerabilityIn multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the P…EPSS 1.2%8.8CVE-2022-32137Codesys plcwinnt heap-based buffer overflow vulnerabilityIn multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause a heap-based buffer overflow, resulting in a deni…EPSS 1.4%8.8CVE-2022-32138Codesys plcwinnt vulnerabilityIn multiple CODESYS products, a remote attacker may craft a request which may cause an unexpected sign extension, resulting in a denial-of-service co…EPSS 1.2%8.8CVE-2019-9013Codesys control for beaglebone sl broken cryptographic algorithm vulnerabilityAn issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials bein…EPSS 0.28%8.1CVE-2022-32142Codesys plcwinnt vulnerabilityMultiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2019-19789), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.