Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-13532


CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.


Published

2019-09-13T17:15:11.617

Last Modified

2024-11-21T04:25:05.470

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-22
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application codesys control_for_beaglebone < 3.5.14.10 Yes
Application codesys control_for_empc-a\/imx6 < 3.5.14.10 Yes
Application codesys control_for_iot2000 < 3.5.14.10 Yes
Application codesys control_for_linux < 3.5.14.10 Yes
Application codesys control_for_pfc100 < 3.5.14.10 Yes
Application codesys control_for_pfc200 < 3.5.14.10 Yes
Application codesys control_for_raspberry_pi < 3.5.14.10 Yes
Application codesys control_rte < 3.5.12.80 Yes
Application codesys control_rte < 3.5.14.10 Yes
Application codesys control_runtime_system_toolkit < 3.5.12.80 Yes
Application codesys control_win ≤ 3.5.12.80 Yes
Application codesys control_win < 3.5.14.10 Yes
Application codesys embedded_target_visu_toolkit < 3.5.12.80 Yes
Application codesys hmi < 3.5.12.80 Yes
Application codesys hmi < 3.5.14.10 Yes
Application codesys remote_target_visu_toolkit < 3.5.12.80 Yes

References