cbcvebase.
CVE-2020-15806
published 2020-07-22

CVE-2020-15806: CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.

PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.05%
79.0th percentile
CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.

Affected

16 ranges
VendorProductVersion rangeFixed in
codesyscontrol_for_beaglebone< 3.5.16.103.5.16.10
codesyscontrol_for_empc-a_imx6< 3.5.16.103.5.16.10
codesyscontrol_for_iot2000< 3.5.16.103.5.16.10
codesyscontrol_for_linux< 3.5.16.103.5.16.10
codesyscontrol_for_pfc100< 3.5.16.103.5.16.10
codesyscontrol_for_pfc200< 3.5.16.103.5.16.10
codesyscontrol_for_plcnext< 3.5.16.103.5.16.10
codesyscontrol_for_raspberry_pi< 3.5.16.103.5.16.10
codesyscontrol_for_wago_touch_panels_600< 3.5.16.103.5.16.10
codesyscontrol_rte>= 3.5.8.60 < 3.5.16.103.5.16.10
codesyscontrol_runtime_system_toolkit>= 3.0 < 3.5.16.103.5.16.10
codesyscontrol_win>= 3.5.9.80 < 3.5.16.103.5.16.10
codesysembedded_target_visu_toolkit>= 3.0 < 3.5.16.103.5.16.10
codesyshmi>= 3.5.10.0 < 3.5.16.103.5.16.10
codesysremote_target_visu_toolkit>= 3.0 < 3.5.16.103.5.16.10
codesyssimulation_runtime>= 3.5.9.40 < 3.5.16.103.5.16.10

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.