CVE-2020-12068

EUVD-2020-4384
An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
Affected Products (NVD)
VendorProductVersion
codesyscontrol_for_beaglebone
𝑥
< 3.5.16.0
codesyscontrol_for_empc-a\/imx6
𝑥
< 3.5.16.0
codesyscontrol_for_iot2000
𝑥
< 3.5.16.0
codesyscontrol_for_pfc100
𝑥
< 3.5.16.0
codesyscontrol_for_pfc200
𝑥
< 3.5.16.0
codesyscontrol_for_plcnext
𝑥
< 3.5.16.0
codesyscontrol_for_raspberry_pi
𝑥
< 3.5.16.0
codesyscontrol_rte
3.0 ≤
𝑥
< 3.5.16.0
codesyscontrol_runtime_system_toolkit
3.0 ≤
𝑥
< 3.5.16.0
codesyscontrol_win
3.0 ≤
𝑥
< 3.5.16.0
codesysdevelopment_system
𝑥
< 3.5.16.0
codesyshmi
3.0 ≤
𝑥
< 3.5.16.0
𝑥
= Vulnerable software versions