PT-2019-19309 · 3S Smart · Codesys V3

CVE-2019-9012

·

Published

2019-08-15

·

Updated

2023-05-16

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions 3S-Smart CODESYS V3 products versions prior to 3.5.14.20
Description A crafted communication request may cause uncontrolled memory allocations in the affected CODESYS products, potentially resulting in a denial-of-service condition. The issue affects all variants of CODESYS V3 products that contain the CmpGateway component, regardless of the CPU type or operating system.
Recommendations For versions prior to 3.5.14.20, update to version 3.5.14.20 or later to resolve the issue. As a temporary workaround, consider restricting access to the CmpGateway component to minimize the risk of exploitation.

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-9012

Affected Products

Codesys V3