First published: Tue Sep 17 2019(Updated: )
3S-Smart Software Solutions GmbH CODESYS V3 Library Manager, all versions prior to 3.5.16.0, allows the system to display active library content without checking its validity, which may allow the contents of manipulated libraries to be displayed or executed. The issue also exists for source libraries, but 3S-Smart Software Solutions GmbH strongly recommends distributing compiled libraries only.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Codesys Codesys | <3.5.16.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13538 is classified as a medium severity vulnerability.
To fix CVE-2019-13538, upgrade CODESYS to version 3.5.16.0 or later.
CVE-2019-13538 allows for potentially manipulated library contents to be displayed or executed.
CVE-2019-13538 affects all versions of CODESYS prior to 3.5.16.0.
CVE-2019-13538 specifically affects the CODESYS Library Manager used by 3S-Smart Software Solutions.