Integer overflow in the GatewayService component in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to execute arbitrary code via a large size value in the packet header, which triggers a heap-based buffer overflow.
https://exchange.xforce.ibmcloud.com/vulnerabilities/71531
http://secunia.com/advisories/47018