CVE-2018-25048

The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to access and modify all system files as well as DoS the device.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CERTVDECNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
VendorProductVersion
codesyscontrol_for_beaglebone
3.0.0.0 ≤
𝑥
< 3.5.12.30
codesyscontrol_for_empc-a\/imx6
3.0.0.0 ≤
𝑥
< 3.5.12.30
codesyscontrol_for_iot2000
3.0.0.0 ≤
𝑥
< 3.5.12.30
codesyscontrol_for_pfc100
3.0.0.0 ≤
𝑥
< 3.5.12.30
codesyscontrol_for_pfc200
3.0.0.0 ≤
𝑥
< 3.5.12.30
codesyscontrol_for_raspberry_pi
3.0.0.0 ≤
𝑥
< 3.5.12.30
codesyscontrol_rte
3.0.0.0 ≤
𝑥
< 3.5.12.30
codesyscontrol_v3_runtime_system_toolkit
3.0.0.0 ≤
𝑥
< 3.5.12.30
codesyscontrol_win
3.0.0.0 ≤
𝑥
< 3.5.12.30
codesysembedded_target_visu_toolkit
3.0 ≤
𝑥
< 3.5.12.30
codesyshmi
3.0 ≤
𝑥
< 3.5.12.30
codesysremote_target_visu_toolkit
3.0 ≤
𝑥
< 3.5.12.30
codesysruntime_plcwinnt
2.0.0.0 ≤
𝑥
< 2.4.7.52
codesysruntime_system_toolkit
2.0.0.0 ≤
𝑥
< 2.4.7.52
codesysruntime_system_toolkit
3.5.15.0
codesyssimulation_runtime
3.0.0.0 ≤
𝑥
< 3.5.12.30
𝑥
= Vulnerable software versions