← Back

CVE-2012-6069

nvd nist
Published: Jan 21, 2013Modified: Apr 29, 2026

JSON object

Loading...
10.0
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 6.0
Source: ics-cert@hq.dhs.gov (Secondary)

Description

The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker to access files and directories outside the intended scope. This may allow an attacker to upload and download any file on the device. This could allow the attacker to affect the availability, integrity, and confidentiality of the device.

Affected (5)

1 product
Codesys Runtime System
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.4.0
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
3s Software
Version 2.3.9.35
Version 2.3.9.36
Version 2.3.9.37
Version 2.3.9.8

References (10)

Timeline

No history available yet.