PT-2012-1189 · 3S Smart Software Solutions · Codesys Runtime System

Publicado

2012-12-05

·

Atualizado

2025-07-02

·

CVE-2012-6069

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CODESYS Runtime System versions 2.3.x through 2.4.x
Description The issue allows remote attackers to read, overwrite, or create arbitrary files via a .. (dot dot) in a request to the TCP listener service. This is due to incorrect restriction of the directory path name with limited access. Exploitation of the issue may allow a remote attacker to read, write, and create arbitrary files using the .. element in the path when requesting the network service.
Recommendations For CODESYS Runtime System versions 2.3.x through 2.4.x, consider restricting access to the TCP listener service until a patch is available. As a temporary workaround, avoid using the .. element in the path when requesting the network service to minimize the risk of exploitation.

Correção

Path traversal

Relative Path Traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-02092
BDU:2017-00135
CVE-2012-6069

Produtos afetados

Codesys Runtime System