Description
CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://customers.codesys.com/fileadmin/data/customers/security/2019/Advisory2019-10_CDS-68341.pdf
Exploit, Third Party Advisory x_refsource_misc
https://www.tenable.com/security/research/tra-2019-48
Scores
CVSS v3
9.8
EPSS
0.0041
EPSS Percentile
61.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-120
Status
published
Products (14)
codesys/control_for_beaglebone
< 3.5.15.20
codesys/control_for_empc-a\/imx6
< 3.5.15.20
codesys/control_for_iot2000
< 3.5.15.20
codesys/control_for_linux
< 3.5.15.20
codesys/control_for_pfc100
< 3.5.15.20
codesys/control_for_pfc200
< 3.5.15.20
codesys/control_for_plcnext
< 3.5.15.20
codesys/control_for_raspberry_pi
< 3.5.15.20
codesys/control_rte
< 3.5.15.20
codesys/control_runtime_system_toolkit
< 3.5.15.20
... and 4 more
Published
Nov 20, 2019
Tracked Since
Feb 18, 2026