CVE-2012-6069 - CVE House
Back to Database
Status published Critical CVE-2012-6069

3S CoDeSys Relative Path Traversal

Vulnerability Description

The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker to access files and directories outside the intended scope. This may allow an attacker to upload and download any file on the device. This could allow the attacker to affect the availability, integrity, and confidentiality of the device.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-6069

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Independent researcher Reid Wightman of IOActive, formerly of Digital Bond has validated that the patch, issued by 3S, mitigates theses vulnerabilities.

Affected Vendor

3S-Smart Software Solutions

View all reports →

Affected Software

CODESYS Control Runtime embedded, CODESYS Control Runtime full, CODESYS Control RTE, CECX-X-C1 Modular Master Controller with CoDeSys, CECX-X-M1 Modular Controller with CoDeSys and SoftMotion, CoDeSys
Vulnerable Versions:
0, All, 3.X

Timeline

Official Publish: January 21st, 2013
Last Modified: July 2nd, 2025
Added to House: July 19th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)