CVE-2019-9013

Summary

CVECVE-2019-9013
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2019-08-15 17:15:00 UTC
Updated2023-05-16 11:15:00 UTC
DescriptionAn issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the following CODESYS V3 products in all versions containing the CmpUserMgr component are affected regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS V3 Simulation Runtime (part of the CODESYS Development System), CODESYS Control V3 Runtime System Toolkit, CODESYS HMI V3.

Risk And Classification

Problem Types: CWE-327

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Codesys Control For Beaglebone Sl All All All All
Application Codesys Control For Beaglebone Sl All All All All
Application Codesys Control For Empc-a/imx6 Sl All All All All
Application Codesys Control For Empc-a/imx6 Sl All All All All
Application Codesys Control For Empc-a/imx6 Sl All All All All
Application Codesys Control For Iot2000 Sl All All All All
Application Codesys Control For Iot2000 Sl All All All All
Application Codesys Control For Linux Sl All All All All
Application Codesys Control For Linux Sl All All All All
Application Codesys Control For Pfc100 Sl All All All All
Application Codesys Control For Pfc100 Sl All All All All
Application Codesys Control For Pfc200 Sl All All All All
Application Codesys Control For Pfc200 Sl All All All All
Application Codesys Control Rte Sl All All All All
Application Codesys Control Rte Sl All All All All
Application Codesys Control Win Sl All All All All
Application Codesys Control Win Sl All All All All
Application Codesys Development System All All All All
Application Codesys Development System All All All All
Application Codesys Hmi Sl All All All All
Application Codesys Hmi Sl All All All All
Application Codesys Raspberry Pi All All All All
Application Codesys Raspberry Pi All All All All
Application Codesys Runtime Toolkit All All All All
Application Codesys Runtime Toolkit All All All All

References

ReferenceSourceLinkTags
customers.codesys.com/index.php CONFIRM customers.codesys.com
3S-Smart Software Solutions GmbH CODESYS V3 (Update A) | CISA MISC www.us-cert.gov Third Party Advisory, US Government Resource
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Legacy QID Mappings

  • 590644 3S-Smart Software Solutions GmbH CODESYS V3 (Update A) Vulnerability (ICSA-19-213-04)
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report