cbcvebase.
CVE-2019-13548
published 2019-09-13

CVE-2019-13548: CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution.

Affected

16 ranges
VendorProductVersion rangeFixed in
codesyscontrol_for_beaglebone< 3.5.14.103.5.14.10
codesyscontrol_for_empc-a_imx6< 3.5.14.103.5.14.10
codesyscontrol_for_iot2000< 3.5.14.103.5.14.10
codesyscontrol_for_linux< 3.5.14.103.5.14.10
codesyscontrol_for_pfc100< 3.5.14.103.5.14.10
codesyscontrol_for_pfc200< 3.5.14.103.5.14.10
codesyscontrol_for_raspberry_pi< 3.5.14.103.5.14.10
codesyscontrol_rte>= 3.5.13.0 < 3.5.14.103.5.14.10
codesyscontrol_rte>= 3.5.8.60 < 3.5.12.803.5.12.80
codesyscontrol_runtime_system_toolkit>= 3.0 < 3.5.12.803.5.12.80
codesyscontrol_win>= 3.5.13.0 < 3.5.14.103.5.14.10
codesyscontrol_win3.5.9.80 – 3.5.12.80
codesysembedded_target_visu_toolkit>= 3.0 < 3.5.12.803.5.12.80
codesyshmi>= 3.5.10.0 < 3.5.12.803.5.12.80
codesyshmi>= 3.5.13.0 < 3.5.14.103.5.14.10
codesysremote_target_visu_toolkit>= 3.0 < 3.5.12.803.5.12.80