The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
02 Jul 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 10.0
v3 : 9.8 |
CWE | CWE-284 | |
References |
|
|
Summary | (en) The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service. |
Information
Published : 2013-01-21 21:55
Updated : 2025-07-02 20:15
NVD link : CVE-2012-6068
Mitre link : CVE-2012-6068
CVE.ORG link : CVE-2012-6068
JSON object : View
Products Affected
3s-software
- codesys_runtime_system