First published: Wed Jul 22 2020(Updated: )
CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CODESYS Control for Beaglebone SL | <3.5.16.10 | |
CODESYS Control for empc-a/imx6 | <3.5.16.10 | |
CODESYS Control for IoT2000 | <3.5.16.10 | |
CODESYS Control for Linux | <3.5.16.10 | |
CODESYS Control for PFC100 SL | <3.5.16.10 | |
CODESYS Control for pfc200 SL | <3.5.16.10 | |
CODESYS Control for plcnext | <3.5.16.10 | |
CODESYS Control for Raspberry Pi SL | <3.5.16.10 | |
CODESYS Control for WAGO Touch Panels 600 SL | <3.5.16.10 | |
CODESYS Control Runtime System Toolkit | >=3.5.8.60<3.5.16.10 | |
CODESYS control rte beckhoff cx | >=3.5.8.60<3.5.16.10 | |
CODESYS Runtime System Toolkit | >=3.0<3.5.16.10 | |
CODESYS Control | >=3.5.9.80<3.5.16.10 | |
CODESYS Remote Target Visu Toolkit | >=3.0<3.5.16.10 | |
CODESYS HMI (SL) | >=3.5.10.0<3.5.16.10 | |
CODESYS Remote Target Visu Toolkit | >=3.0<3.5.16.10 | |
CODESYS Simulation Runtime | >=3.5.9.40<3.5.16.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15806 is a vulnerability in CODESYS Control runtime system before version 3.5.16.10 that allows uncontrolled memory allocation.
CVE-2020-15806 affects multiple software including Codesys Control for Beaglebone, Empc-a/imx6, IoT2000, Linux, Pfc100, Pfc200, Plcnext, Raspberry Pi, Wago Touch Panels 600, and more.
CVE-2020-15806 has a severity rating of 7.5, which is considered high.
To mitigate CVE-2020-15806, it is recommended to update the CODESYS Control runtime system to version 3.5.16.10 or newer.
You can find more information about CVE-2020-15806 on the CODESYS website and the Tenable Security Research page.