In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCodesys Control For Beaglebone Sl
APPCodesysall versionsCodesys Control For Empc A\/imx6 Sl
APPCodesysall versionsCodesys Control For Iot2000 Sl
APPCodesysall versionsCodesys Control For Linux Sl
APPCodesysall versionsCodesys Control For Pfc100 Sl
APPCodesysall versionsCodesys Control For Pfc200 Sl
APPCodesysall versionsCodesys Control For Plcnext Sl
APPCodesysall versionsCodesys Control For Raspberry Pi Sl
APPCodesysall versionsCodesys Control For Wago Touch Panels 600 Sl
APPCodesysall versionsCodesys Control Rte Sl
APPCodesysall versionsCodesys Control Rte Sl \(for Beckhoff Cx\)
APPCodesysall versionsCodesys Control Runtime System Toolkit
APPCodesysall versionsCodesys Control Win Sl
APPCodesysall versionsCodesys Hmi Sl
APPCodesysall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2021-33485CRITICAL9.8PL ✓same product
Heap-based Buffer Overflow w CODESYS Control Runtime przed wersją 3.5.17.10
CVE-2020-10245CRITICAL9.8PL ✓same product
Buffer overflow w serwerze web CODESYS V3 umożliwiający RCE
CVE-2019-18858CRITICAL9.8PL ✓same product
Buffer Overflow w serwerze WWW CODESYS 3 — zdalne wykonanie kodu
CVE-2019-13548CRITICAL9.8PL ✓same product
Stack overflow w CODESYS V3 web server umożliwiający RCE
CVE-2019-9010CRITICAL9.8PL ✓same product
CODESYS Gateway V3 — błędna weryfikacja właściciela kanału komunikacyjnego