PT-2015-7256 · 3S Smart Software Solutions · Codesys Gateway Server

Josep Pi Rodriguez

·

Published

2015-09-16

·

Updated

2022-12-02

·

CVE-2015-6460

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CODESYS Gateway Server versions prior to 2.3.9.34
Description The issue is related to multiple heap-based buffer overflows that allow remote attackers to execute arbitrary code. This can be achieved via specific opcodes, including 0x3ef and 0x3f0. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations For versions prior to 2.3.9.34, update to version 2.3.9.34 or later to resolve the issue. As a temporary workaround, consider restricting access to the 0x3ef and 0x3f0 opcodes until a patch is applied.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2015-6460
ZDI-15-441
ZDI-15-442

Affected Products

Codesys Gateway Server