CVE-2012-6069
Last modified
CVE-2012-6069 is a critical-severity vulnerability rated 10/10 on the CVSS scale. The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker to access files and directories outside the intended scope. This may allow an attacker to upload and download any file on the device. EPSS estimates a 2.64% chance of exploitation in the next 30 days.
Description
The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker to access files and directories outside the intended scope. This may allow an attacker to upload and download any file on the device. This could allow the attacker to affect the availability, integrity, and confidentiality of the device.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| 3s-Software | Codesys Runtime System | 2.4.0 |
| 3s-Software | Codesys Runtime System | 2.3.9.8 |
| 3s-Software | Codesys Runtime System | 2.3.9.35 |
| 3s-Software | Codesys Runtime System | 2.3.9.36 |
| 3s-Software | Codesys Runtime System | 2.3.9.37 |
References
- http://ics-cert.us-cert.gov/advisories/ICSA-14-084-01US Government Resource
- http://www.us-cert.gov/control_systems/pdf/ICSA-13-011-01.pdfUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-6069?
How severe is CVE-2012-6069?
How do I fix CVE-2012-6069?
Are you affected by CVE-2012-6069?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
