The following CODESYS V3 runtime systems, all versions prior to
3.5.14.10, containing the web server (CmpWebServer)
IMPROPER LIMITATION OF A PATHNAME TO A RESTRICTED DIRECTORY ('PATH TRAVERSAL') CWE-22
Specially crafted http or https requests may allow an attacker access to files outside the restricted working directory of the controller.
STACK-BASED BUFFER OVERFLOW CWE-121
Specially crafted http or https requests could cause a stack overflow, which may create a denial-of-service condition or allow remote code execution.
CVSS v3 10.0
https://www.us-cert.gov/ics/advisories/icsa-19-255-01