PT-2012-1188 · 3S Smart Software Solutions · Codesys Runtime System+1
CVE-2012-6068
·
Publicado
2012-12-05
·
Atualizado
2025-07-02
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
CODESYS Runtime System versions 2.3.x through 2.4.x
Description
The issue is related to the lack of authentication requirements in the default configuration of the CODESYS Runtime Toolkit. This allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.
Recommendations
For versions 2.3.x through 2.4.x, consider implementing authentication requirements for the Runtime Toolkit to prevent unauthorized access. As a temporary workaround, restrict access to the TCP listener service to minimize the risk of exploitation.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Codesys Runtime System
Codesys Runtime Toolkit