First published: Wed Jul 22 2020(Updated: )
CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Codesys Control For Beaglebone | <3.5.16.10 | |
Codesys Control For Empc-a\/imx6 | <3.5.16.10 | |
Codesys Control For Iot2000 | <3.5.16.10 | |
Codesys Control For Linux | <3.5.16.10 | |
Codesys Control For Pfc100 | <3.5.16.10 | |
Codesys Control For Pfc200 | <3.5.16.10 | |
Codesys Control For Plcnext | <3.5.16.10 | |
Codesys Control For Raspberry Pi | <3.5.16.10 | |
Codesys Control For Wago Touch Panels 600 | <3.5.16.10 | |
Codesys Control Rte | >=3.5.8.60<3.5.16.10 | |
Codesys Control Rte | >=3.5.8.60<3.5.16.10 | |
Codesys Control Runtime System Toolkit | >=3.0<3.5.16.10 | |
Codesys Control Win | >=3.5.9.80<3.5.16.10 | |
Codesys Embedded Target Visu Toolkit | >=3.0<3.5.16.10 | |
Codesys Hmi | >=3.5.10.0<3.5.16.10 | |
Codesys Remote Target Visu Toolkit | >=3.0<3.5.16.10 | |
Codesys Simulation Runtime | >=3.5.9.40<3.5.16.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15806 is a vulnerability in CODESYS Control runtime system before version 3.5.16.10 that allows uncontrolled memory allocation.
CVE-2020-15806 affects multiple software including Codesys Control for Beaglebone, Empc-a/imx6, IoT2000, Linux, Pfc100, Pfc200, Plcnext, Raspberry Pi, Wago Touch Panels 600, and more.
CVE-2020-15806 has a severity rating of 7.5, which is considered high.
To mitigate CVE-2020-15806, it is recommended to update the CODESYS Control runtime system to version 3.5.16.10 or newer.
You can find more information about CVE-2020-15806 on the CODESYS website and the Tenable Security Research page.