QID 590607
Date Published: 2021-12-06
QID 590607: 3S-Smart Software Solutions CODESYS Denial of Service (DoS) Vulnerability (Advisory 2020-02)
All variants of the following CODESYS V3 products in all versions prior V3.5.16.10 containing the CmpRouter or CmpRouterEmbedded component are affected.
QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys
Crafted communication packets can trigger an out-of-bounds memory buffer access in the communication stack, which may result in a denial-of-service condition.
Solution
Customers are advised to refer to Advisory 2020-03 for affected packages and patching details.
Vendor References
CVEs related to QID 590607
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Advisory 2020-02 |
|