CVE-2012-6068

The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:3s-software:codesys_runtime_system:2.3.9.8:*:*:*:*:*:*:*
cpe:2.3:a:3s-software:codesys_runtime_system:2.3.9.35:*:*:*:*:*:*:*
cpe:2.3:a:3s-software:codesys_runtime_system:2.3.9.36:*:*:*:*:*:*:*
cpe:2.3:a:3s-software:codesys_runtime_system:2.3.9.37:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:3s-software:codesys_runtime_system:2.4.0:*:*:*:*:*:*:*

History

02 Jul 2025, 20:15

Type Values Removed Values Added
CVSS v2 : 10.0
v3 : unknown
v2 : 10.0
v3 : 9.8
CWE CWE-284
References
  • () https://us.codesys.com/ecosystem/security/ -
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-13-011-01 -
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-14-084-01 -
Summary (en) The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to (1) execute commands via the command-line interface in the TCP listener service or (2) transfer files via requests to the TCP listener service. (en) The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.

Information

Published : 2013-01-21 21:55

Updated : 2025-07-02 20:15


NVD link : CVE-2012-6068

Mitre link : CVE-2012-6068

CVE.ORG link : CVE-2012-6068


JSON object : View

Products Affected

3s-software

  • codesys_runtime_system
CWE
CWE-284

Improper Access Control

CWE-264

Permissions, Privileges, and Access Controls