First published: Mon Jan 21 2013(Updated: )
The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to (1) execute commands via the command-line interface in the TCP listener service or (2) transfer files via requests to the TCP listener service.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
3s-software Codesys Runtime System | =2.3.9.8 | |
3s-software Codesys Runtime System | =2.3.9.35 | |
3s-software Codesys Runtime System | =2.3.9.36 | |
3s-software Codesys Runtime System | =2.3.9.37 | |
3s-software Codesys Runtime System | =2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.