CVE-2012-6068: 3S CoDeSys Improper Access Control
The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to (1) execute commands via the command-line interface in the TCP listener service or (2) transfer files via requests to the TCP listener service.
Other sources
The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6068?
CVE-2012-6068 has a high severity rating due to the potential for unauthorized remote command execution and file transfer.
How do I fix CVE-2012-6068?
To fix CVE-2012-6068, ensure that appropriate authentication mechanisms are implemented for the CODESYS Runtime System components.
What versions are affected by CVE-2012-6068?
CVE-2012-6068 affects CODESYS Runtime System versions 2.3.x and 2.4.x, including specific versions like 2.3.9.8 and 2.4.0.
Can exploit attempts of CVE-2012-6068 be detected?
Yes, exploit attempts of CVE-2012-6068 can potentially be detected through monitoring of network traffic for unusual command executions or file requests.
What are the potential impacts of CVE-2012-6068?
The potential impacts of CVE-2012-6068 include unauthorized access, data breaches, and compromise of system integrity.