CVE-2017-6027 - CVE House
Back to Database
Status published Critical CVE-2017-6027

An Arbitrary File Upload issue was discovered in 3S-Smart Software...

Vulnerability Description

An Arbitrary File Upload issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2.3 and prior. A specially crafted web server request may allow the upload of arbitrary files (with a dangerous type) to the CODESYS Web Server without authorization which may allow remote code execution.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-6027

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

3S-Smart Software Solutions GmbH CODESYS Web Server
Vulnerable Versions:
3S-Smart Software Solutions GmbH CODESYS Web Server

Timeline

Official Publish: May 19th, 2017
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)