QID 591169

Date Published: 2022-11-10

QID 591169: 3S-Smart CodeSYS V3 Multiple Vulnerabilities (Advisory 2021-13 Version: 6.0)

Multiple vulnerabilities were discovered in 3S-Smart CodeSYS V3. Deserialization of Untrusted Data affects Codesys.
The CODESYS Development System V3 archive files without sufficiently verifying the data.

Affected Versions:
CODESYS Development System V3 prior version V3.5.17.10

QID Detection Logic:
The QID checks for App Paths\CODESYS.exe in HKLM in the windows registry to check the vulnerable version of the product.

A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    The vendor has released a patch version , for more information kindly visit Advisory 2021-13 Version: 6.0
    Software Advisories
    Advisory ID Software Component Link
    Advisory 2021-13 Version: 6.0 URL Logo customers.codesys.com/index.php?eID=dumpFile&t=f&f=16805&token=ee583c498941d9fda86490bca98ff21928eec08a&download=