PT-2019-8756 · 3S Smart Software Solutions · Codesys Control V3

Publicado

2019-01-29

·

Atualizado

2019-10-09

·

CVE-2018-10612

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions 3S-Smart Software Solutions GmbH CODESYS Control V3 versions prior to 3.5.14.0
Description The issue concerns the lack of default enablement for user access management and communication encryption. This could potentially allow an attacker to access the device and sensitive information, including user credentials.
Recommendations For versions prior to 3.5.14.0, update to version 3.5.14.0 or later to enable user access management and communication encryption by default.

Correção

Incorrect Permission

Improper Access Control

Missing Encryption of Sensitive Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-10612

Produtos afetados

Codesys Control V3