cbcvebase.
CVE-2019-13532
published 2019-09-13

CVE-2019-13532: CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files…

PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
3.18%
86.6th percentile
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.

Affected

16 ranges
VendorProductVersion rangeFixed in
codesyscontrol_for_beaglebone< 3.5.14.103.5.14.10
codesyscontrol_for_empc-a_imx6< 3.5.14.103.5.14.10
codesyscontrol_for_iot2000< 3.5.14.103.5.14.10
codesyscontrol_for_linux< 3.5.14.103.5.14.10
codesyscontrol_for_pfc100< 3.5.14.103.5.14.10
codesyscontrol_for_pfc200< 3.5.14.103.5.14.10
codesyscontrol_for_raspberry_pi< 3.5.14.103.5.14.10
codesyscontrol_rte>= 3.5.13.0 < 3.5.14.103.5.14.10
codesyscontrol_rte>= 3.5.8.60 < 3.5.12.803.5.12.80
codesyscontrol_runtime_system_toolkit>= 3.0 < 3.5.12.803.5.12.80
codesyscontrol_win>= 3.5.13.0 < 3.5.14.103.5.14.10
codesyscontrol_win3.5.9.80 – 3.5.12.80
codesysembedded_target_visu_toolkit>= 3.0 < 3.5.12.803.5.12.80
codesyshmi>= 3.5.10.0 < 3.5.12.803.5.12.80
codesyshmi>= 3.5.13.0 < 3.5.14.103.5.14.10
codesysremote_target_visu_toolkit>= 3.0 < 3.5.12.803.5.12.80

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.