CVE-2011-5058: Medium severity codesys vulnerability
The CmbWebserver.dll module of the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to create arbitrary directories under the web root by specifying a non-existent directory using \ (backslash) characters in an HTTP GET request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-5058?
The severity of CVE-2011-5058 is rated as high due to its potential for remote exploitation.
How do I fix CVE-2011-5058?
To fix CVE-2011-5058, update to a patched version of CODESYS that addresses this vulnerability.
What systems are affected by CVE-2011-5058?
CVE-2011-5058 affects CODESYS version 3.4 SP4 Patch 2 and potentially earlier versions if vulnerable configurations are used.
What type of attack does CVE-2011-5058 facilitate?
CVE-2011-5058 allows remote attackers to create arbitrary directories under the web root using specially crafted HTTP GET requests.
Is there a workaround for CVE-2011-5058?
A workaround for CVE-2011-5058 includes restricting access to the CmbWebserver.dll module and limiting user input validation.