CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCodesys Control For Beaglebone
APPCodesys< 3.5.14.10Codesys Control For Empc A\/imx6
APPCodesys< 3.5.14.10Codesys Control For Iot2000
APPCodesys< 3.5.14.10Codesys Control For Linux
APPCodesys< 3.5.14.10Codesys Control For Pfc100
APPCodesys< 3.5.14.10Codesys Control For Pfc200
APPCodesys< 3.5.14.10Codesys Control For Raspberry Pi
APPCodesys< 3.5.14.10Codesys Control Rte
APPCodesys3.5.8.60 – 3.5.12.80 (excl.)3.5.13.0 – 3.5.14.10 (excl.)Codesys Control Runtime System Toolkit
APPCodesys3.0 – 3.5.12.80 (excl.)Codesys Control Win
APPCodesys3.5.9.80 – 3.5.12.803.5.13.0 – 3.5.14.10 (excl.)Codesys Embedded Target Visu Toolkit
APPCodesys3.0 – 3.5.12.80 (excl.)Codesys Hmi
APPCodesys3.5.10.0 – 3.5.12.80 (excl.)3.5.13.0 – 3.5.14.10 (excl.)Codesys Remote Target Visu Toolkit
APPCodesys3.0 – 3.5.12.80 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
Related vulnerabilities
CVE-2021-33485CRITICAL9.8PL ✓same product
Heap-based Buffer Overflow w CODESYS Control Runtime przed wersją 3.5.17.10
CVE-2020-10245CRITICAL9.8PL ✓same product
Buffer overflow w serwerze web CODESYS V3 umożliwiający RCE
CVE-2019-18858CRITICAL9.8PL ✓same product
Buffer Overflow w serwerze WWW CODESYS 3 — zdalne wykonanie kodu
CVE-2023-6357HIGH8.8same product
A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via fil...
CVE-2022-4046HIGH8.8same product
In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buf...