Back to overview

CVE-2012-6069

CRITICAL
10.0
CVSS 3.1
Description
The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker to access files and directories outside the intended scope. This may allow an attacker to upload and download any file on the device. This could allow the attacker to affect the availability, integrity, and confidentiality of the device.

Metadata

CVE ID
CVE-2012-6069
State
PUBLISHED
Assigner
icscert
Reserved
2012-12-05 00:00 UTC
Published
2013-01-21 21:00 UTC
Last updated
2025-07-02 20:15 UTC
Primary CWE
CWE-23
CWE-23
Vendor / Product
3S-Smart Software Solutions / CODESYS Control Runtime embedded
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (6)
VendorProductPlatformVersions
3S-Smart Software Solutions CoDeSys 3.X
3S-Smart Software Solutions CODESYS Control RTE 0 < 2.3.7.17
3S-Smart Software Solutions CODESYS Control Runtime embedded 0 < 2.3.2.8
3S-Smart Software Solutions CODESYS Control Runtime full 0 < 2.4.7.40
Festo CECX-X-C1 Modular Master Controller with CoDeSys All
Festo CECX-X-M1 Modular Controller with CoDeSys and SoftMotion All
Weakness (CWE)
CWESourceDescription
CWE-23 cna CWE-23
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview