The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.
2013-01-21T21:55:01.103
2025-07-02T20:15:28.747
Deferred
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | 3s-software | codesys_runtime_system | 2.3.9.8 | Yes |
Application | 3s-software | codesys_runtime_system | 2.3.9.35 | Yes |
Application | 3s-software | codesys_runtime_system | 2.3.9.36 | Yes |
Application | 3s-software | codesys_runtime_system | 2.3.9.37 | Yes |
Application | 3s-software | codesys_runtime_system | 2.4.0 | Yes |