Codesys Runtime Improper Limitation of a Pathname
Vulnerability Description
The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to access and modify all system files as well as DoS the device.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-25048
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Prosoft-Systems Ltd.
References
More from CODESYS
View All →Affected Vendor
CODESYS
View all reports →