← Back

CVE-2018-25048

nvd nist
Published: Mar 23, 2023Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: info@cert.vde.com (Secondary)

Description

The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to access and modify all system files as well as DoS the device.

Affected (16)

15 products
Control For Beaglebone
Control For Empc A/imx6
Control For Iot2000
Control For Pfc100
Control For Pfc200
Control For Raspberry Pi
Control Rte
Control V3 Runtime System Toolkit
Control Win
Embedded Target Visu Toolkit
Hmi
Remote Target Visu Toolkit
Runtime Plcwinnt
Runtime System Toolkit
Simulation Runtime
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
From 3.0.0.0 to 3.5.12.30
From 3.0.0.0 to 3.5.12.30
From 3.0.0.0 to 3.5.12.30
From 3.0.0.0 to 3.5.12.30
From 3.0.0.0 to 3.5.12.30
From 3.0.0.0 to 3.5.12.30
From 3.0.0.0 to 3.5.12.30
From 3.0.0.0 to 3.5.12.30
From 3.0.0.0 to 3.5.12.30
From 3.0 to 3.5.12.30
From 3.0 to 3.5.12.30
From 3.0 to 3.5.12.30
From 2.0.0.0 to 2.4.7.52
Codesys
From 2.0.0.0 to 2.4.7.52
Version 3.5.15.0
From 3.0.0.0 to 3.5.12.30

Timeline

No history available yet.