PT-2012-1188 · 3S Smart Software Solutions · Codesys Runtime System+1

Published

2012-12-05

·

Updated

2025-07-02

·

CVE-2012-6068

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CODESYS Runtime System versions 2.3.x through 2.4.x
Description The issue is related to the lack of authentication requirements in the default configuration of the CODESYS Runtime Toolkit. This allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.
Recommendations For versions 2.3.x through 2.4.x, consider implementing authentication requirements for the Runtime Toolkit to prevent unauthorized access. As a temporary workaround, restrict access to the TCP listener service to minimize the risk of exploitation.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2016-02091
BDU:2017-00134
CVE-2012-6068

Affected Products

Codesys Runtime System
Codesys Runtime Toolkit