An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over the runtime.
Se detectó un problema en 3S-Smart CODESYS V3 versiones hasta 3.5.12.30. Un usuario con pocos privilegios puede tomar el control total sobre el tiempo de ejecución.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:N/AC:L/Au:S/C:P/I:P/A:P
| Access Vector | NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | SINGLE |
| Confidentiality Impact | PARTIAL |
| Integrity Impact | PARTIAL |
| Availability Impact | PARTIAL |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-732
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| codesys | control_for_beaglebone | * | <built-in method update of dict object at 0x7e60e846fac0> | Application |
| codesys | control_for_empc-a\/imx6 | * | <built-in method update of dict object at 0x7e61079cb2c0> | Application |
| codesys | control_for_iot2000 | * | <built-in method update of dict object at 0x7e6107e50540> | Application |
| codesys | control_for_pfc100 | * | <built-in method update of dict object at 0x7e6110a9ff80> | Application |
| codesys | control_for_pfc200 | * | <built-in method update of dict object at 0x7e6110a9ed40> | Application |
| codesys | control_for_raspberry_pi | * | <built-in method update of dict object at 0x7e60bae0c7c0> | Application |
| codesys | control_rte | * | <built-in method update of dict object at 0x7e6107e51240> | Application |
| codesys | control_win | * | <built-in method update of dict object at 0x7e6107e52980> | Application |
| codesys | hmi | * | <built-in method update of dict object at 0x7e60ba9bc680> | Application |
| codesys | simulation_runtime | * | <built-in method update of dict object at 0x7e6110a9cd00> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:codesys:control_for_beaglebone:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:codesys:control_for_empc-a\/imx6:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:codesys:control_for_iot2000:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:codesys:control_for_pfc100:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:codesys:control_for_pfc200:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:codesys:control_for_raspberry_pi:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:codesys:control_rte:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:codesys:control_win:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:codesys:hmi:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:codesys:simulation_runtime:*:*:*:*:*:*:*:* |