After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.
https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-01
https://www.cisa.gov/news-events/ics-advisories/icsa-26-020-02
https://www.cisa.gov/news-events/ics-advisories/icsa-25-112-04
https://www.cisa.gov/news-events/ics-advisories/icsa-25-093-04
https://www.cisa.gov/news-events/ics-advisories/icsa-25-093-03