PT-2019-8756 · 3S Smart Software Solutions · Codesys Control V3

Published

2019-01-29

·

Updated

2019-10-09

·

CVE-2018-10612

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions 3S-Smart Software Solutions GmbH CODESYS Control V3 versions prior to 3.5.14.0
Description The issue concerns the lack of default enablement for user access management and communication encryption. This could potentially allow an attacker to access the device and sensitive information, including user credentials.
Recommendations For versions prior to 3.5.14.0, update to version 3.5.14.0 or later to enable user access management and communication encryption by default.

Fix

Incorrect Permission

Improper Access Control

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10612

Affected Products

Codesys Control V3