CVE-2018-25048
published 2023-03-23CVE-2018-25048: The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to access and modify all system…
high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to access and modify all system files as well as DoS the device.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| codesys | control_for_beaglebone | >= 3.0.0.0 < 3.5.12.30 | 3.5.12.30 |
| codesys | control_for_empc-a_imx6 | >= 3.0.0.0 < 3.5.12.30 | 3.5.12.30 |
| codesys | control_for_iot2000 | >= 3.0.0.0 < 3.5.12.30 | 3.5.12.30 |
| codesys | control_for_pfc100 | >= 3.0.0.0 < 3.5.12.30 | 3.5.12.30 |
| codesys | control_for_pfc200 | >= 3.0.0.0 < 3.5.12.30 | 3.5.12.30 |
| codesys | control_for_raspberry_pi | >= 3.0.0.0 < 3.5.12.30 | 3.5.12.30 |
| codesys | control_rte | >= 3.0.0.0 < 3.5.12.30 | 3.5.12.30 |
| codesys | control_rte_v3 | >= 3.0.0.0 < 3.5.12.30 | 3.5.12.30 |
| codesys | control_v3_runtime_system_toolkit | >= 3.0.0.0 < 3.5.12.30 | 3.5.12.30 |
| codesys | control_win | >= 3.0.0.0 < 3.5.12.30 | 3.5.12.30 |
| codesys | control_win_v3 | >= 3.0.0.0 < 3.5.12.30 | 3.5.12.30 |
| codesys | embedded_target_visu_toolkit | >= 3.0 < 3.5.12.30 | 3.5.12.30 |
| codesys | hmi | >= 3.0 < 3.5.12.30 | 3.5.12.30 |
| codesys | hmi_v3 | >= 3.0.0.0 < 3.5.12.30 | 3.5.12.30 |
| codesys | remote_target_visu_toolkit | >= 3.0 < 3.5.12.30 | 3.5.12.30 |
| codesys | runtime_plcwinnt | >= 2.0.0.0 < 2.4.7.52 | 2.4.7.52 |
| codesys | runtime_system_toolkit | — | — |
| codesys | runtime_system_toolkit | >= 2.0.0.0 < 2.4.7.52 | 2.4.7.52 |
| codesys | runtime_toolkit_32_bit_embedded | >= 2.0.0.0 < 2.3.2.10 | 2.3.2.10 |
| codesys | runtime_toolkit_32_bit_full | >= 2.0.0.0 < 2.4.7.52 | 2.4.7.52 |
| codesys | simulation_runtime | >= 3.0.0.0 < 3.5.12.30 | 3.5.12.30 |
| codesys | v3_embedded_target_visu_toolkit | >= 3.0.0.0 < 3.5.12.30 | 3.5.12.30 |
| codesys | v3_remote_target_visu | >= 3.0.0.0 < 3.5.12.30 | 3.5.12.30 |
| codesys | v3_remote_target_visu_toolkit | >= 3.0.0.0 < 3.5.12.30 | 3.5.12.30 |
| codesys | v3_simulation_runtime | >= 3.0.0.0 < 3.5.12.30 | 3.5.12.30 |