CVE-2012-6069: 3S CoDeSys Relative Path Traversal
Directory traversal vulnerability in the Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x allows remote attackers to read, overwrite, or create arbitrary files via a .. (dot dot) in a request to the TCP listener service.
Other sources
The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker to access files and directories outside the intended scope. This may allow an attacker to upload and download any file on the device. This could allow the attacker to affect the availability, integrity, and confidentiality of the device.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6069?
CVE-2012-6069 is considered to be of high severity due to the potential for unauthorized file access and modification.
How do I fix CVE-2012-6069?
To fix CVE-2012-6069, it is recommended to update the CODESYS Runtime System to a version that addresses this vulnerability.
Which versions of CODESYS Runtime System are affected by CVE-2012-6069?
CVE-2012-6069 affects CODESYS Runtime System versions 2.3.x and 2.4.x, specifically versions 2.3.9.35, 2.3.9.36, 2.3.9.37, and 2.4.0.
What types of attacks are possible through CVE-2012-6069?
CVE-2012-6069 allows remote attackers to exploit the vulnerability for directory traversal, enabling them to read, overwrite, or create arbitrary files.
Is there a workaround for CVE-2012-6069?
While a complete fix is to update the software, restricting network access to the TCP listener service can serve as a temporary workaround.