CVE-2019-13532: Path Traversal
Published Sep 13, 2019
·Updated
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.
Affected Software
16 affected components
CODESYS Control For Beaglebone<3.5.14.10
CODESYS Control For Empc-a\/imx6<3.5.14.10
CODESYS Control For Iot2000<3.5.14.10
CODESYS Control For Linux<3.5.14.10
CODESYS Control For Pfc100<3.5.14.10
CODESYS Control For Pfc200<3.5.14.10
CODESYS Control For Raspberry Pi<3.5.14.10
CODESYS Control Rte>=3.5.8.60<3.5.12.80
CODESYS Control Rte>=3.5.13.0<3.5.14.10
CODESYS Control Runtime System Toolkit>=3.0<3.5.12.80
CODESYS Control Win>=3.5.9.80<=3.5.12.80
CODESYS Control Win>=3.5.13.0<3.5.14.10
CODESYS Embedded Target Visu Toolkit>=3.0<3.5.12.80
CODESYS Hmi>=3.5.10.0<3.5.12.80
CODESYS Hmi>=3.5.13.0<3.5.14.10
CODESYS Remote Target Visu Toolkit>=3.0<3.5.12.80
Remediation
Patch Available
Event History
Sep 13, 2019
CVE Published
via MITRE·04:58 PM
Data Sourced
via MITRE·04:58 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this CODESYS vulnerability?
The vulnerability ID for this CODESYS vulnerability is CVE-2019-13532.
2
What is the severity rating of CVE-2019-13532?
CVE-2019-13532 has a severity rating of 7.5 (High).
3
Which versions of CODESYS are affected by CVE-2019-13532?
All versions of CODESYS prior to 3.5.14.10 are affected by CVE-2019-13532.
4
What is the impact of CVE-2019-13532 vulnerability?
CVE-2019-13532 allows an attacker to send specially crafted HTTP or HTTPS requests which may allow access to files outside the restricted working directory of the controller.
5
Is there a fix available for CVE-2019-13532?
Yes, upgrading to CODESYS version 3.5.14.10 or above fixes CVE-2019-13532.