CRITICAL🇵🇱 Wersja polska

CVE-2012-6068

CVSS 9.8v3.1pub. 2013-01-21upd. 2026-04-29

The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • 3s Software Codesys Runtime System

    APP
    3S-Software
    2.3.9.352.3.9.362.3.9.372.3.9.82.4.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2018-5440CRITICAL9.8PL ✓same product

Stack-based Buffer Overflow w CODESYS Web Server — możliwe RCE

CVE-2012-6069CRITICAL10.0PL ✓same product

Path Traversal w CoDeSys Runtime Toolkit — nieograniczony dostęp do plików

CVE-2014-0760HIGH9.3same product

The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and ...

CVE-2014-0769HIGH9.3same product

The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and S...

CVE-2015-6482MEDIUM5.0same product

Runtime Toolkit before 2.4.7.48 in 3S-Smart CODESYS before 2.3.9.48 allows remote attackers to cause a denial ...