CVE-2012-6068
21.01.2013, 21:55
The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to (1) execute commands via the command-line interface in the TCP listener service or (2) transfer files via requests to the TCP listener service.Enginsight
Vendor | Product | Version |
---|---|---|
3s-software | codesys_runtime_system | 2.3.9.8 |
3s-software | codesys_runtime_system | 2.3.9.35 |
3s-software | codesys_runtime_system | 2.3.9.36 |
3s-software | codesys_runtime_system | 2.3.9.37 |
3s-software | codesys_runtime_system | 2.4.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References