cbcvebase.
CVE-2020-12068
published 2020-05-14

CVE-2020-12068: An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.

PriorityP432medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.92%
56.3th percentile
An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.

Affected

12 ranges
VendorProductVersion rangeFixed in
codesyscontrol_for_beaglebone< 3.5.16.03.5.16.0
codesyscontrol_for_empc-a_imx6< 3.5.16.03.5.16.0
codesyscontrol_for_iot2000< 3.5.16.03.5.16.0
codesyscontrol_for_pfc100< 3.5.16.03.5.16.0
codesyscontrol_for_pfc200< 3.5.16.03.5.16.0
codesyscontrol_for_plcnext< 3.5.16.03.5.16.0
codesyscontrol_for_raspberry_pi< 3.5.16.03.5.16.0
codesyscontrol_rte>= 3.0 < 3.5.16.03.5.16.0
codesyscontrol_runtime_system_toolkit>= 3.0 < 3.5.16.03.5.16.0
codesyscontrol_win>= 3.0 < 3.5.16.03.5.16.0
codesysdevelopment_system< 3.5.16.03.5.16.0
codesyshmi>= 3.0 < 3.5.16.03.5.16.0

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.