An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HCodesys Control For Beaglebone Sl
APPCodesys< 4.5.0.0Codesys Control For Beckhoff Cx9020
APPCodesys< 4.5.0.0Codesys Control For Empc A\/imx6 Sl
APPCodesys< 4.5.0.0Codesys Control For Iot2000 Sl
APPCodesys< 4.5.0.0Codesys Control For Linux Sl
APPCodesys< 4.5.0.0Codesys Control For Pfc100 Sl
APPCodesys< 4.5.0.0Codesys Control For Pfc200 Sl
APPCodesys< 4.5.0.0Codesys Control For Plcnext Sl
APPCodesys< 4.5.0.0Codesys Control For Raspberry Pi Sl
APPCodesys< 4.5.0.0Codesys Control For Wago Touch Panels 600 Sl
APPCodesys< 4.5.0.0Codesys Control Rte Sl
APPCodesys< 3.5.18.0Codesys Control Rte Sl \(for Beckhoff Cx\)
APPCodesys< 3.5.18.0Codesys Control Runtime System Toolkit
APPCodesys< 3.5.18.0Codesys Control Win Sl
APPCodesys< 3.5.18.0Codesys Development System
APPCodesys3.0 – 3.5.18.0 (bez)Codesys Edge Gateway
APPCodesys< 3.5.18.0< 4.5.0.0Codesys Embedded Target Visu Toolkit
APPCodesys< 3.5.18.0Codesys Gateway
APPCodesys< 3.5.18.0Codesys Hmi Sl
APPCodesys< 3.5.18.0Codesys Remote Target Visu Toolkit
APPCodesys< 3.5.18.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Powiązane podatności
CVE-2022-31802CRITICAL9.8PL ✓ten sam produkt
Nieprawidłowa weryfikacja hasła w CODESYS Gateway Server V2
CVE-2021-33485CRITICAL9.8PL ✓ten sam produkt
Heap-based Buffer Overflow w CODESYS Control Runtime przed wersją 3.5.17.10
CVE-2020-10245CRITICAL9.8PL ✓ten sam produkt
Buffer overflow w serwerze web CODESYS V3 umożliwiający RCE
CVE-2019-18858CRITICAL9.8PL ✓ten sam produkt
Buffer Overflow w serwerze WWW CODESYS 3 — zdalne wykonanie kodu
CVE-2019-13548CRITICAL9.8PL ✓ten sam produkt
Stack overflow w CODESYS V3 web server umożliwiający RCE