Severity
6.5MEDIUM
EPSS
0.6%
top 30.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 24
Latest updateMay 24

Description

CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages8 packages

NVDcodesys/control< 3.5.15.30
NVDcodesys/gateway3.5.15.103.5.15.30
NVDcodesys/control_rte3.5.8.603.5.15.30
NVDcodesys/control_win3.5.9.803.5.15.30

🔴Vulnerability Details

2
GHSA
GHSA-6627-xq79-x5q7: CODESYS Control V3, Gateway V3, and HMI V3 before 32022-05-24
CVEList
CVE-2020-7052: CODESYS Control V3, Gateway V3, and HMI V3 before 32020-01-24
CVE-2020-7052 (MEDIUM CVSS 6.5) | CODESYS Control V3 | cvebase.io