CVE-2011-5009: Null Pointer Dereference
The CmpWebServer.dll module in the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a crafted Content-Length in an HTTP POST or (2) an invalid HTTP request method.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-5009?
CVE-2011-5009 has been classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2011-5009?
To mitigate CVE-2011-5009, update to the latest version of 3S CoDeSys, as the vulnerability is addressed in newer patches.
What type of attack does CVE-2011-5009 enable?
CVE-2011-5009 allows remote attackers to execute a denial of service attack through a NULL pointer dereference.
Which software is affected by CVE-2011-5009?
CVE-2011-5009 specifically affects the 3S CoDeSys version 3.4 SP4 Patch 2.
How can I identify if my system is vulnerable to CVE-2011-5009?
You can identify if your system is vulnerable to CVE-2011-5009 by checking if the CmpWebServer.dll module is present in your CoDeSys installation and if it's the affected version.