CVE-2012-6068

The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:3s-software:codesys_runtime_system:2.3.9.8:*:*:*:*:*:*:*
cpe:2.3:a:3s-software:codesys_runtime_system:2.3.9.35:*:*:*:*:*:*:*
cpe:2.3:a:3s-software:codesys_runtime_system:2.3.9.36:*:*:*:*:*:*:*
cpe:2.3:a:3s-software:codesys_runtime_system:2.3.9.37:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:3s-software:codesys_runtime_system:2.4.0:*:*:*:*:*:*:*

History

02 Jul 2025, 20:15

Type Values Removed Values Added
CWE CWE-284
Summary (en) The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to (1) execute commands via the command-line interface in the TCP listener service or (2) transfer files via requests to the TCP listener service. (en) The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.
CVSS v2 : 10.0
v3 : unknown
v2 : 10.0
v3 : 9.8
References
  • () https://us.codesys.com/ecosystem/security/ -
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-13-011-01 -
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-14-084-01 -

21 Nov 2024, 01:45

Type Values Removed Values Added
References () http://ics-cert.us-cert.gov/advisories/ICSA-14-084-01 - US Government Resource () http://ics-cert.us-cert.gov/advisories/ICSA-14-084-01 - US Government Resource
References () http://www.codesys.com/news-events/press-releases/detail/article/sicherheitsluecke-in-codesys-v23-laufzeitsystem.html - Vendor Advisory () http://www.codesys.com/news-events/press-releases/detail/article/sicherheitsluecke-in-codesys-v23-laufzeitsystem.html - Vendor Advisory
References () http://www.digitalbond.com/tools/basecamp/3s-codesys/ - () http://www.digitalbond.com/tools/basecamp/3s-codesys/ -
References () http://www.us-cert.gov/control_systems/pdf/ICSA-13-011-01.pdf - US Government Resource () http://www.us-cert.gov/control_systems/pdf/ICSA-13-011-01.pdf - US Government Resource

Information

Published : 2013-01-21 21:55

Updated : 2025-07-02 20:15


NVD link : CVE-2012-6068

Mitre link : CVE-2012-6068

CVE.ORG link : CVE-2012-6068


JSON object : View

Products Affected

3s-software

  • codesys_runtime_system
CWE
CWE-284

Improper Access Control

CWE-264

Permissions, Privileges, and Access Controls