CVE-2024-5000
EUVD-2024-4627504.06.2024, 09:15
An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS products which can cause a DoS due to incorrect calculation of buffer size.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| codesys | control_for_empc-a\/imx6_sl | 𝑥 < 4.12.0.0 | ADP |
| codesys | control_for_beaglebone_sl | 𝑥 < 4.12.0.0 | ADP |
| codesys | control_for_iot2000_sl | 𝑥 < 4.12.0.0 | ADP |
| codesys | control_for_linux_arm_sl | 𝑥 < 4.12.0.0 | ADP |
| codesys | control_for_linux_sl | 𝑥 < 4.12.0.0 | ADP |
| codesys | control_for_pfc200_sl | 𝑥 < 4.12.0.0 | ADP |
| codesys | control_for_plcnext_sl | 𝑥 < 4.12.0.0 | ADP |
| codesys | control_for_raspberry_pi_sl | 𝑥 < 4.12.0.0 | ADP |
| codesys | control_for_wago_touch_panels_600_sl | 𝑥 < 4.12.0.0 | ADP |
| codesys | control_rte_\(for_beckhoff_cx\)_sl | 𝑥 < 3.5.20.10 | ADP |
| codesys | control_rte_\(sl\) | 𝑥 < 3.5.20.10 | ADP |
| codesys | control_win_\(sl\) | 𝑥 < 3.5.20.10 | ADP |
| codesys | runtime_toolkit | 𝑥 < 3.5.20.10 | ADP |
| codesys | hmi_\(sl\) | 𝑥 < 3.5.20.10 | ADP |
Common Weakness Enumeration
References