CVE-2020-12068

An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
codesyscontrol_for_beaglebone
𝑥
< 3.5.16.0
codesyscontrol_for_empc-a\/imx6
𝑥
< 3.5.16.0
codesyscontrol_for_iot2000
𝑥
< 3.5.16.0
codesyscontrol_for_pfc100
𝑥
< 3.5.16.0
codesyscontrol_for_pfc200
𝑥
< 3.5.16.0
codesyscontrol_for_plcnext
𝑥
< 3.5.16.0
codesyscontrol_for_raspberry_pi
𝑥
< 3.5.16.0
codesyscontrol_rte
3.0 ≤
𝑥
< 3.5.16.0
codesyscontrol_runtime_system_toolkit
3.0 ≤
𝑥
< 3.5.16.0
codesyscontrol_win
3.0 ≤
𝑥
< 3.5.16.0
codesysdevelopment_system
𝑥
< 3.5.16.0
codesyshmi
3.0 ≤
𝑥
< 3.5.16.0
𝑥
= Vulnerable software versions