CVE-2024-5000
published 2024-06-04CVE-2024-5000: An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS products which can cause a DoS due to…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.57%
43.4th percentile
An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS products which can cause a DoS due to incorrect calculation of buffer size.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| codesys | codesys_control_for_beaglebone_sl | < 4.12.0.0 | 4.12.0.0 |
| codesys | codesys_control_for_empc-a_imx6_sl | < 4.12.0.0 | 4.12.0.0 |
| codesys | codesys_control_for_iot2000_sl | < 4.12.0.0 | 4.12.0.0 |
| codesys | codesys_control_for_linux_arm_sl | < 4.12.0.0 | 4.12.0.0 |
| codesys | codesys_control_for_linux_sl | < 4.12.0.0 | 4.12.0.0 |
| codesys | codesys_control_for_pfc100_sl | < 4.12.0.0 | 4.12.0.0 |
| codesys | codesys_control_for_pfc200_sl | < 4.12.0.0 | 4.12.0.0 |
| codesys | codesys_control_for_plcnext_sl | < 4.12.0.0 | 4.12.0.0 |
| codesys | codesys_control_for_raspberry_pi_sl | < 4.12.0.0 | 4.12.0.0 |
| codesys | codesys_control_for_wago_touch_panels_600_sl | < 4.12.0.0 | 4.12.0.0 |
| codesys | codesys_control_rte | < 3.5.20.10 | 3.5.20.10 |
| codesys | codesys_control_rte_sl | < 3.5.20.10 | 3.5.20.10 |
| codesys | codesys_control_win | < 3.5.20.10 | 3.5.20.10 |
| codesys | codesys_hmi | < 3.5.20.10 | 3.5.20.10 |
| codesys | codesys_runtime_toolkit | < 3.5.20.10 | 3.5.20.10 |
| dgtlmoon | changedetection.io | >= 0.39.14 < 0.45.13 | 0.45.13 |
| chrome_chrome | — | — | |
| juniper | junos_os | — | — |
| juniper | srx_series | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_cisco5.8MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
CODESYS in Festo Automation Suite
cisa_ics·2026-03-17
CODESYS in Festo Automation Suite
ICS Advisory
##
CODESYS in Festo Automation Suite
Release DateMarch 17, 2026
Alert CodeICSA-26-076-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
3. TECHNICAL DETAILS
The following versions of CODESYS in Festo Automation Suite are affected:
- FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0) vers:all/*
- FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10) vers:all/*
- FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0) vers:all/*
- FESTO Software Festo Automation
Chrome
Stable Channel Update for Desktop: CVE-2024-9957
vendor_chrome·2024-10-15·CVSS 8.8
CVE-2024-9957 [MEDIUM] Stable Channel Update for Desktop: CVE-2024-9957
Stable Channel Update for Desktop
CVE-2024-9957: Use after free in UI. Reported by lime(@limeSec_) and fmyy(@binary_fmyy) From TIANGONG Team of Legendsec at QI-ANXIN Group on 2024-08-08 [$5000][ 40076120 ] Medium CVE-2024-9958: Inappropriate implementation in PictureInPicture
Reported by Lyra Rebane (rebane2001) on 2023-11-02 [$4000][ 368672129 ] Medium CVE-2024-9959: Use after free in DevTools
Severity: medium
Juniper
CVE-2024-47503: An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX4600 an
vendor_juniper·2024-10-11·CVSS 6.5
CVE-2024-47503 [MEDIUM] CWE-754 CVE-2024-47503: An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX4600 an
CVE-2024-47503: An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX4600 and SRX5000 Series allows an unauthenticated and logically adjacent attacker to cause a Denial-of-Service (DoS).
If in a multicast scenario a sequence of
specific PIM packets is received, this will cause a flowd crash and restart, which leads to momentary service interruption.
This issue affects Junos OS on SRX 4600 and SRX 5000 Series:
* All versions before 21.4R3-S9,
* 22.2 versions before 22.2R3-S5,
* 22.3 versions before 22.3R3-S4,
* 22.4 versions before 22.4R3-S4,
* 23.2 versions before 23.2R2-S2,
* 23.4 versions before 23.4R2,
* 24.2 versions before 24.2R1-S1, 24.2R2.
Cisco
Cisco IOS Software on Cisco Industrial Ethernet Series Switches Access Control List Bypass Vulnerability
vendor_cisco·2024-09-25·CVSS 5.8
CVE-2024-20465 [MEDIUM] CWE-284 Cisco IOS Software on Cisco Industrial Ethernet Series Switches Access Control List Bypass Vulnerability
Cisco IOS Software on Cisco Industrial Ethernet Series Switches Access Control List Bypass Vulnerability
A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco Industrial Ethernet 4000, 4010, and 5000 Series Switches could allow an unauthenticated, remote attacker to bypass a configured ACL.
This vulnerability is due to the incorrect handling of IPv4 ACLs on switched virtual interfaces when an administrator enables and disables Resilient Ethernet Protocol (REP). An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds t
Red Hat
kernel: libfs: fix infinite directory reads for offset dir
vendor_redhat·2024-09-13·CVSS 5.5
CVE-2024-46701 [MEDIUM] CWE-835 kernel: libfs: fix infinite directory reads for offset dir
kernel: libfs: fix infinite directory reads for offset dir
In the Linux kernel, the following vulnerability has been resolved:
libfs: fix infinite directory reads for offset dir
After we switch tmpfs dir operations from simple_dir_operations to
simple_offset_dir_operations, every rename happened will fill new dentry
to dest dir's maple tree(&SHMEM_I(inode)->dir_offsets->mt) with a free
key starting with octx->newx_offset, and then set newx_offset equals to
free key + 1. This will lead to infinite readdir combine with rename
happened at the same time, which fail generic/736 in xfstests(detail show
as below).
1. create 5000 files(1 2 3...) under one dir
2. call readdir(man 3 readdir) once, and get one entry
3. rename(entry, "TEMPFILE"), then rename("TEMPFILE", entry)
4. loop 2~3, until read
Chrome
Stable Channel Update for Desktop: CVE-2024-8034
vendor_chrome·2024-08-21·CVSS 4.3
CVE-2024-8034 [LOW] Stable Channel Update for Desktop: CVE-2024-8034
Stable Channel Update for Desktop
CVE-2024-8034: Inappropriate implementation in Custom Tabs. Reported by Bharat (mrnoob) on 2024-07-18 [TBD][ 40059470 ] Low CVE-2024-8035: Inappropriate implementation in Extensions
Reported by Microsoft on 2022-04-26 The previous version of these notes did not include the following security fixes which were included in the release: [$5000][ 40068607 ] Medium CVE-2024-13178: Inappropriate implementation in Fullscreen
Severity: low
Chrome
Stable Channel Update for Desktop: CVE-2024-6994
vendor_chrome·2024-07-23·CVSS 8.8
CVE-2024-6994 [MEDIUM] Stable Channel Update for Desktop: CVE-2024-6994
Stable Channel Update for Desktop
CVE-2024-6994: Heap buffer overflow in Layout. Reported by Huang Xilin of Ant Group Light-Year Security Lab on 2024-05-10 [$6000][ 343938078 ] Medium CVE-2024-6995: Inappropriate implementation in Fullscreen
Reported by Alesandro Ortiz on 2024-06-01 [$5000][ 333708039 ] Medium CVE-2024-6996: Race in Frames
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2024-5833
vendor_chrome·2024-06-11·CVSS 8.8
CVE-2024-5833 [HIGH] Stable Channel Update for Desktop: CVE-2024-5833
Stable Channel Update for Desktop
CVE-2024-5833: Type Confusion in V8. Reported by @ginggilBesel on 2024-05-24 [$5000][ 342840932 ] High CVE-2024-5834: Inappropriate implementation in Dawn
Reported by gelatin dessert on 2024-05-26 [$3000][ 341991535 ] High CVE-2024-5835: Heap buffer overflow in Tab Groups
Severity: high
Chrome
Stable Channel Update for Desktop: CVE-2024-5839
vendor_chrome·2024-06-11·CVSS 6.5
CVE-2024-5839 [MEDIUM] Stable Channel Update for Desktop: CVE-2024-5839
Stable Channel Update for Desktop
CVE-2024-5839: Inappropriate Implementation in Memory Allocator. Reported by Micky on 2024-05-13 [$5000][ 41492103 ] Medium CVE-2024-5840: Policy Bypass in CORS
Reported by Matt Howard on 2024-01-17 [$2000][ 326765855 ] Medium CVE-2024-5841: Use after free in V8
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2024-5157
vendor_chrome·2024-05-21·CVSS 8.8
CVE-2024-5157 [HIGH] Stable Channel Update for Desktop: CVE-2024-5157
Stable Channel Update for Desktop
CVE-2024-5157: Use after free in Scheduling. Reported by Looben Yang on 2024-04-21 [$10000][ 338908243 ] High CVE-2024-5158: Type Confusion in V8
Reported by Zhenghang Xiao (@Kipreyyy) on 2024-05-06 [$5000][ 335613092 ] High CVE-2024-5159: Heap buffer overflow in ANGLE
Severity: high
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2024-3841
vendor_chrome·2024-05-01·CVSS 6.1
CVE-2024-3841 [MEDIUM] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2024-3841
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2024-3841: Insufficient data validation in Browser Switcher. Reported by Oleg on 2024-03-19 [$5000][ 40058873 ] Low CVE-2024-3844: Inappropriate implementation in Extensions
Reported by Alesandro Ortiz on 2022-02-23 [$2000][ 40064754 ] Low CVE-2024-3846: Inappropriate implementation in Prompts
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2024-3838
vendor_chrome·2024-04-16·CVSS 5.5
CVE-2024-3838 [MEDIUM] Stable Channel Update for Desktop: CVE-2024-3838
Stable Channel Update for Desktop
CVE-2024-3838: Inappropriate implementation in Autofill. Reported by KiriminAja on 2024-03-06 [$5000][ 41491859 ] Medium CVE-2024-3839: Out of bounds read in Fonts
Reported by Ronald Crane (Zippenhop LLC) on 2024-01-16 [$3000][ 41493458 ] Medium CVE-2024-3840: Insufficient policy enforcement in Site Isolation
Severity: medium
Juniper
CVE-2024-30405: An Incorrect Calculation of Buffer Size vulnerability in Juniper Networks Junos OS SRX 5000 Series devices using SPC2 line cards while ALGs are enable
vendor_juniper·2024-04-12·CVSS 7.5
CVE-2024-30405 [HIGH] CWE-131 CVE-2024-30405: An Incorrect Calculation of Buffer Size vulnerability in Juniper Networks Junos OS SRX 5000 Series devices using SPC2 line cards while ALGs are enable
CVE-2024-30405: An Incorrect Calculation of Buffer Size vulnerability in Juniper Networks Junos OS SRX 5000 Series devices using SPC2 line cards while ALGs are enabled allows an attacker sending specific crafted packets to cause a transit traffic Denial of Service (DoS).
Continued receipt and processing of these specific packets will sustain the Denial of Service condition.
This issue affects:
Juniper Networks Junos OS SRX 5000 Series with SPC2 with ALGs enabled.
* All versions earlier than 21.2R3-S7;
* 21.4 versions earlier than 21.4R3-S6;
* 22.1 versions earlier than 22.1R3-S5;
* 22.2 versions earlier than 22.2R3-S3;
* 22.3 versions earlier than 22.3R3-S2;
* 22.4 versions earlier than 22.4R3;
* 23.2 versions earlier than 23.2R2.
Chrome
Stable Channel Update for Desktop: CVE-2024-1669
vendor_chrome·2024-02-20·CVSS 8.8
CVE-2024-1669 [HIGH] Stable Channel Update for Desktop: CVE-2024-1669
Stable Channel Update for Desktop
CVE-2024-1669: Out of bounds memory access in Blink. Reported by Anonymous on 2024-01-26 [$5000][ 41481374 ] High CVE-2024-1670: Use after free in Mojo
Reported by Cassidy Kim(@cassidy6564) on 2023-12-06 [$3000][ 40069622 ] Medium CVE-2024-5500: Inappropriate Implementation in Sign-In
Severity: high
Chrome
Stable Channel Update for Desktop: CVE-2024-1077
vendor_chrome·2024-01-30·CVSS 8.8
CVE-2024-1077 [HIGH] Stable Channel Update for Desktop: CVE-2024-1077
Stable Channel Update for Desktop
CVE-2024-1077: Use after free in Network. Reported by Giulio Candreva with Microsoft Browser Security on 2023-12-12 [$5000][ 1511567 ] High CVE-2024-1060: Use after free in Canvas
Reported by Anonymous on 2023-12-14 [$3000][ 1514777 ] High CVE-2024-1059: Use after free in WebRTC
Severity: high
Juniper
CVE-2024-21594:
A Heap-based Buffer Overflow vulnerability in the Network Services Daemon (NSD) of Juniper Networks Junos OS allows authenticated, low privileged, lo
vendor_juniper·2024-01-12·CVSS 5.5
CVE-2024-21594 [MEDIUM] CWE-122 CVE-2024-21594:
A Heap-based Buffer Overflow vulnerability in the Network Services Daemon (NSD) of Juniper Networks Junos OS allows authenticated, low privileged, lo
CVE-2024-21594:
A Heap-based Buffer Overflow vulnerability in the Network Services Daemon (NSD) of Juniper Networks Junos OS allows authenticated, low privileged, local attacker to cause a Denial of Service (DoS).
On an SRX 5000 Series device, when executing a specific command repeatedly, memory is corrupted, which leads to a Flow Processing Daemon (flowd) crash.
The NSD process has to be restarted to restore services.
If this issue occurs, it can be checked with the following command:
user@host> request security policies check
The following log message can also be observed:
Error: policies are out of sync for PFE node.fpc.pic.
This issue affects:
Juniper Networks Junos OS on SRX 5000 Series
* All versions earlier than 20.4R3-S6;
* 21.1 versions earlier than 21.1R3-S5;
* 21.2 versi
Chrome
Stable Channel Update for Desktop: CVE-2023-6510
vendor_chrome·2023-12-05·CVSS 8.8
CVE-2023-6510 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-6510
Stable Channel Update for Desktop
CVE-2023-6510: Use after free in Media Capture. Reported by [pwn2car] on 2023-09-08 [$2000][ 1478613 ] Low CVE-2023-6511: Inappropriate implementation in Autofill
Reported by Ahmed ElMasry on 2023-09-04 [$5000][ 40069571 ] Low CVE-2024-3175: Insufficient data validation in Extensions
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2024-3174
vendor_chrome·2023-10-31·CVSS 4.3
CVE-2024-3174 [HIGH] Stable Channel Update for Desktop: CVE-2024-3174
Stable Channel Update for Desktop
CVE-2024-3174: Inappropriate implementation in V8. Reported by Alan Goodman on 2023-09-25 [$3000][ 1281972 ] Medium CVE-2023-5850: Incorrect security UI in Downloads
Reported by Mohit Raj (shadow2639) on 2021-12-22 [$5000][ 40066780 ] Medium CVE-2023-7011: Inappropriate implementation in Picture in Picture
Severity: high
Cisco
Cisco IOS Software on Cisco Industrial Ethernet Series Switches Access Control List Bypass Vulnerability
vendor_cisco·CVSS 3.1
CVE-2024-20465 Cisco IOS Software on Cisco Industrial Ethernet Series Switches Access Control List Bypass Vulnerability
CVE-2024-20465: Cisco IOS Software on Cisco Industrial Ethernet Series Switches Access Control List Bypass Vulnerability
A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco Industrial Ethernet 4000, 4010, and 5000 Series Switches could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to the incorrect handling of IPv4 ACLs on switched virtual interfaces when an administrator enables and disables Resilient Ethernet Protocol (REP). An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device. Cisco has released software updates that address this vulnerability. There are no
GHSA
GHSA-xchm-28cx-p56h: An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS products which can cause a DoS due
ghsa_unreviewed·2024-06-04
CVE-2024-5000 [HIGH] CWE-131 GHSA-xchm-28cx-p56h: An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS products which can cause a DoS due
An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS products which can cause a DoS due to incorrect calculation of buffer size.
GHSA
Lektor does not sanitize database path traversal
ghsa·2024-03-27
CVE-2024-28335 [CRITICAL] CWE-22 Lektor does not sanitize database path traversal
Lektor does not sanitize database path traversal
Lektor before 3.3.11 does not sanitize DB path traversal. Thus, shell commands might be executed via a file that is added to the templates directory, if the victim's web browser accesses an untrusted website that uses JavaScript to send requests to localhost port 5000, and the web browser is running on the same machine as the "lektor server" command.
GHSA
changedetection.io API endpoint is not secured with API token
ghsa·2024-01-23
CVE-2024-23329 [LOW] CWE-863 changedetection.io API endpoint is not secured with API token
changedetection.io API endpoint is not secured with API token
### Summary
API endpoint `/api/v1/watch//history` can be accessed by any unauthorized user.
### Details
WatchHistory resource does not have `@auth.check_token` annotation, which means it can be accessed without providing `x-api-key` header.
https://github.com/dgtlmoon/changedetection.io/blob/9510345e01ea8e308c339163d8e8b030ce5ac7f1/changedetectionio/api/api_v1.py#L129-L156
### PoC
1. Get list of watch with `x-api-key`:
```sh
$ curl -H "x-api-key: apikeyhere" http://localhost:5000/api/v1/watch
{"uuid": ...}
```
2. Call for history of snapshots without `x-api-key`. Expected - 401/403 error. Actual - list of snapshots is listed.
```sh
$ curl http://localhost:5000/api/v1/watch/uuid/history
{"timestamp": "/path/to/snapshot.txt
No detection rules found.
No writeups or analysis indexed.
https://cert.vde.com/en/advisories/VDE-2024-026https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=18355&token=e3e5a937ce72602bec39718ddc2f4ba6d983ccd1&download=https://cert.vde.com/en/advisories/VDE-2024-026https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=18355&token=e3e5a937ce72602bec39718ddc2f4ba6d983ccd1&download=
2024-06-04
Published