QID 590777
Date Published: 2022-03-29
QID 590777: 3s-Smart CodeSys Gmbh Multiple Vulnerabilities (Advisory2018-11)
Crafted web server requests may read or write arbitrary memory or files in the CODESYS Control runtime system or may cause invalid memory accesses to execute code or to crash the CODESYS web server or the CODESYS Control runtime system.
AFFECTED PRODUCTS
All variants of the following CODESYS V3 products in all versions prior V3.5.13.30
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version using windows registry keys.
NOTE: Marking it as potential, as we cannot check CmpBlkDrvTcp component.
Successful remote exploitation of these vulnerabilities affects confidentiality, integrity, and availability.
Solution
The customers are advised to refer to advisoryAdvisory2018-11 for patch details
Vendor References
CVEs related to QID 590777
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Advisory2018-11 |
|