CVE-2020-15806: High severity codesys control for beaglebone sl vulnerability
Published Jul 22, 2020
·Updated
CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
Affected Software
17 affected components
CODESYS Control For Beaglebone<3.5.16.10
CODESYS Control For Empc-a\/imx6<3.5.16.10
CODESYS Control For Iot2000<3.5.16.10
CODESYS Control For Linux<3.5.16.10
CODESYS Control For Pfc100<3.5.16.10
CODESYS Control For Pfc200<3.5.16.10
CODESYS Control For Plcnext<3.5.16.10
CODESYS Control For Raspberry Pi<3.5.16.10
CODESYS Control For Wago Touch Panels 600<3.5.16.10
CODESYS Control Rte>=3.5.8.60<3.5.16.10
CODESYS Control Rte Beckhoff Cx>=3.5.8.60<3.5.16.10
CODESYS Control Runtime System Toolkit>=3.0<3.5.16.10
CODESYS Control Win>=3.5.9.80<3.5.16.10
CODESYS Embedded Target Visu Toolkit>=3.0<3.5.16.10
CODESYS HMI>=3.5.10.0<3.5.16.10
CODESYS Remote Target Visu Toolkit>=3.0<3.5.16.10
CODESYS Simulation Runtime>=3.5.9.40<3.5.16.10
Event History
Jul 22, 2020
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
Description
Frequently Asked Questions
1
What is CVE-2020-15806?
CVE-2020-15806 is a vulnerability in CODESYS Control runtime system before version 3.5.16.10 that allows uncontrolled memory allocation.
2
What software is affected by CVE-2020-15806?
CVE-2020-15806 affects multiple software including Codesys Control for Beaglebone, Empc-a/imx6, IoT2000, Linux, Pfc100, Pfc200, Plcnext, Raspberry Pi, Wago Touch Panels 600, and more.
3
What is the severity of CVE-2020-15806?
CVE-2020-15806 has a severity rating of 7.5, which is considered high.
4
How can I mitigate CVE-2020-15806?
To mitigate CVE-2020-15806, it is recommended to update the CODESYS Control runtime system to version 3.5.16.10 or newer.
5
Where can I find more information about CVE-2020-15806?
You can find more information about CVE-2020-15806 on the CODESYS website and the Tenable Security Research page.