CVE-2012-6068
Last modified
CVE-2012-6068 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.. EPSS estimates a 5.27% chance of exploitation in the next 30 days.
Description
The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| 3s-Software | Codesys Runtime System | 2.3.9.8 |
| 3s-Software | Codesys Runtime System | 2.3.9.35 |
| 3s-Software | Codesys Runtime System | 2.3.9.36 |
| 3s-Software | Codesys Runtime System | 2.3.9.37 |
| 3s-Software | Codesys Runtime System | 2.4.0 |
References
- http://ics-cert.us-cert.gov/advisories/ICSA-14-084-01US Government Resource
- http://www.us-cert.gov/control_systems/pdf/ICSA-13-011-01.pdfUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-6068?
How severe is CVE-2012-6068?
How do I fix CVE-2012-6068?
Are you affected by CVE-2012-6068?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
