3S CoDeSys Improper Access Control
Vulnerability Description
The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-6068
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Independent researcher Reid Wightman of IOActive, formerly of Digital Bond has validated that the patch, issued by 3S, mitigates theses vulnerabilities.
References
- http://www.codesys.com/news-events/press-releases/detail/article/sicherheitsluecke-in-codesys-v23-laufzeitsystem.html
- https://www.cisa.gov/news-events/ics-advisories/icsa-13-011-01
- http://www.digitalbond.com/tools/basecamp/3s-codesys/
- https://www.cisa.gov/news-events/ics-advisories/icsa-14-084-01
- https://us.codesys.com/ecosystem/security/
More from 3S-Smart Software Solutions
View All →Affected Vendor
3S-Smart Software Solutions
View all reports →