CVE-2019-13532
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.
Affected (16)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.5.14.10 | |
| Before 3.5.14.10 | |
| Before 3.5.14.10 | |
| Before 3.5.14.10 | |
| Before 3.5.14.10 | |
| Before 3.5.14.10 | |
| Before 3.5.14.10 | |
| From 3.5.13.0 to 3.5.14.10 | |
| From 3.0 to 3.5.12.80 | |
| From 3.5.13.0 to 3.5.14.10 | |
| From 3.0 to 3.5.12.80 | |
| From 3.5.10.0 to 3.5.12.80 | |
| From 3.0 to 3.5.12.80 |
References (2)
Source: ics-cert@hq.dhs.gov
MitigationPatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationPatchThird Party AdvisoryUS Government Resource
Timeline
No history available yet.