PT-2012-1188 · 3S Smart Software Solutions · Codesys Runtime System+1

CVE-2012-6068

·

Publicado

2012-12-05

·

Atualizado

2025-07-02

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CODESYS Runtime System versions 2.3.x through 2.4.x
Description The issue is related to the lack of authentication requirements in the default configuration of the CODESYS Runtime Toolkit. This allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.
Recommendations For versions 2.3.x through 2.4.x, consider implementing authentication requirements for the Runtime Toolkit to prevent unauthorized access. As a temporary workaround, restrict access to the TCP listener service to minimize the risk of exploitation.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-02091
BDU:2017-00134
CVE-2012-6068

Produtos afetados

Codesys Runtime System
Codesys Runtime Toolkit