cbcvebase.
CVE-2024-5000
published 2024-06-04

CVE-2024-5000: An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS products which can cause a DoS due to…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS products which can cause a DoS due to incorrect calculation of buffer size.

Affected

19 ranges
VendorProductVersion rangeFixed in
codesyscodesys_control_for_beaglebone_sl< 4.12.0.04.12.0.0
codesyscodesys_control_for_empc-a_imx6_sl< 4.12.0.04.12.0.0
codesyscodesys_control_for_iot2000_sl< 4.12.0.04.12.0.0
codesyscodesys_control_for_linux_arm_sl< 4.12.0.04.12.0.0
codesyscodesys_control_for_linux_sl< 4.12.0.04.12.0.0
codesyscodesys_control_for_pfc100_sl< 4.12.0.04.12.0.0
codesyscodesys_control_for_pfc200_sl< 4.12.0.04.12.0.0
codesyscodesys_control_for_plcnext_sl< 4.12.0.04.12.0.0
codesyscodesys_control_for_raspberry_pi_sl< 4.12.0.04.12.0.0
codesyscodesys_control_for_wago_touch_panels_600_sl< 4.12.0.04.12.0.0
codesyscodesys_control_rte< 3.5.20.103.5.20.10
codesyscodesys_control_rte_sl< 3.5.20.103.5.20.10
codesyscodesys_control_win< 3.5.20.103.5.20.10
codesyscodesys_hmi< 3.5.20.103.5.20.10
codesyscodesys_runtime_toolkit< 3.5.20.103.5.20.10
dgtlmoonchangedetection.io>= 0.39.14 < 0.45.130.45.13
googlechrome_chrome
juniperjunos_os
junipersrx_series