cbcvebase.
CVE-2019-18858
published 2019-11-20

CVE-2019-18858: CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.

PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.96%
78.0th percentile
CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.

Affected

14 ranges
VendorProductVersion rangeFixed in
codesyscontrol_for_beaglebone< 3.5.15.203.5.15.20
codesyscontrol_for_empc-a_imx6< 3.5.15.203.5.15.20
codesyscontrol_for_iot2000< 3.5.15.203.5.15.20
codesyscontrol_for_linux< 3.5.15.203.5.15.20
codesyscontrol_for_pfc100< 3.5.15.203.5.15.20
codesyscontrol_for_pfc200< 3.5.15.203.5.15.20
codesyscontrol_for_plcnext< 3.5.15.203.5.15.20
codesyscontrol_for_raspberry_pi< 3.5.15.203.5.15.20
codesyscontrol_rte< 3.5.15.203.5.15.20
codesyscontrol_runtime_system_toolkit< 3.5.15.203.5.15.20
codesyscontrol_win< 3.5.15.203.5.15.20
codesysembedded_target_visu_toolkit< 3.5.15.203.5.15.20
codesyshmi< 3.5.15.203.5.15.20
codesysremote_target_visu_toolkit< 3.5.15.203.5.15.20

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.