The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
02 Jul 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-284 | |
Summary | (en) The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service. | |
CVSS |
v2 : v3 : |
v2 : 10.0
v3 : 9.8 |
References |
|
21 Nov 2024, 01:45
Type | Values Removed | Values Added |
---|---|---|
References | () http://ics-cert.us-cert.gov/advisories/ICSA-14-084-01 - US Government Resource | |
References | () http://www.codesys.com/news-events/press-releases/detail/article/sicherheitsluecke-in-codesys-v23-laufzeitsystem.html - Vendor Advisory | |
References | () http://www.digitalbond.com/tools/basecamp/3s-codesys/ - | |
References | () http://www.us-cert.gov/control_systems/pdf/ICSA-13-011-01.pdf - US Government Resource |
Information
Published : 2013-01-21 21:55
Updated : 2025-07-02 20:15
NVD link : CVE-2012-6068
Mitre link : CVE-2012-6068
CVE.ORG link : CVE-2012-6068
JSON object : View
Products Affected
3s-software
- codesys_runtime_system