In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.
https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-01
https://www.cisa.gov/news-events/ics-advisories/icsa-26-020-02
https://www.cisa.gov/news-events/ics-advisories/icsa-25-112-04
https://www.cisa.gov/news-events/ics-advisories/icsa-25-093-04
https://www.cisa.gov/news-events/ics-advisories/icsa-25-093-03