CVE-2019-13532

CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
icscertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
VendorProductVersion
codesyscontrol_for_beaglebone
𝑥
< 3.5.14.10
codesyscontrol_for_empc-a\/imx6
𝑥
< 3.5.14.10
codesyscontrol_for_iot2000
𝑥
< 3.5.14.10
codesyscontrol_for_linux
𝑥
< 3.5.14.10
codesyscontrol_for_pfc100
𝑥
< 3.5.14.10
codesyscontrol_for_pfc200
𝑥
< 3.5.14.10
codesyscontrol_for_raspberry_pi
𝑥
< 3.5.14.10
codesyscontrol_rte
3.5.8.60 ≤
𝑥
< 3.5.12.80
codesyscontrol_rte
3.5.13.0 ≤
𝑥
< 3.5.14.10
codesyscontrol_runtime_system_toolkit
3.0 ≤
𝑥
< 3.5.12.80
codesyscontrol_win
3.5.9.80 ≤
𝑥
≤ 3.5.12.80
codesyscontrol_win
3.5.13.0 ≤
𝑥
< 3.5.14.10
codesysembedded_target_visu_toolkit
3.0 ≤
𝑥
< 3.5.12.80
codesyshmi
3.5.10.0 ≤
𝑥
< 3.5.12.80
codesyshmi
3.5.13.0 ≤
𝑥
< 3.5.14.10
codesysremote_target_visu_toolkit
3.0 ≤
𝑥
< 3.5.12.80
𝑥
= Vulnerable software versions