CVE-2018-25048
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: info@cert.vde.com (Secondary)
Description
The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to access and modify all system files as well as DoS the device.
Affected (16)
Products: Codesys: Control For Beaglebone, Control For Empc A/imx6, Control For Iot2000, Control For Pfc100, Control For Pfc200, Control For Raspberry Pi, Control Rte, Control V3 Runtime System Toolkit, Control Win, Embedded Target Visu Toolkit, Hmi, Remote Target Visu Toolkit, Runtime Plcwinnt, Runtime System Toolkit, Simulation Runtime
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0.0 to 3.5.12.30 | |
| From 3.0.0.0 to 3.5.12.30 | |
| From 3.0.0.0 to 3.5.12.30 | |
| From 3.0.0.0 to 3.5.12.30 | |
| From 3.0.0.0 to 3.5.12.30 | |
| From 3.0.0.0 to 3.5.12.30 | |
| From 3.0.0.0 to 3.5.12.30 | |
| From 3.0.0.0 to 3.5.12.30 | |
| From 3.0.0.0 to 3.5.12.30 | |
| From 3.0 to 3.5.12.30 | |
| From 3.0 to 3.5.12.30 | |
| From 3.0 to 3.5.12.30 | |
| From 2.0.0.0 to 2.4.7.52 | |
| From 2.0.0.0 to 2.4.7.52 | |
| From 3.0.0.0 to 3.5.12.30 |
References (2)
Source: info@cert.vde.com
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Timeline
No history available yet.