CVE-2019-9010 describes a critical vulnerability in 3S-Smart CODESYS V3 products, specifically affecting the CODESYS Gateway's failure to properly verify communication channel ownership. This impacts numerous CODESYS V3 products across various platforms, including Control for BeagleBone, Raspberry Pi, and the Development System, in all versions prior to v3.5.14.20. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with low attack complexity, allowing for complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0, < 3.5.14.20CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:* | ||
>= 3.0, < 3.5.14.20CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:* | ||
>= 3.0, < 3.5.14.20CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:* | ||
>= 3.0, < 3.5.14.20CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:* | ||
>= 3.0, < 3.5.14.20CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple Vulnerabilities in 3S CODESYS Runtime in Rexroth PRC7000
Dec 16, 2020Multiple Vulnerabilities in 3S CODESYS Runtime in Rexroth PRC7000
Dec 16, 2020Multiple Vulnerabilities in 3S CODESYS Runtime in Rexroth PRC7000
Dec 16, 2020Multiple Vulnerabilities in 3S CODESYS Runtime in Rexroth PRC7000
Dec 16, 2020Multiple Vulnerabilities in 3S CODESYS Runtime in Rexroth PRC7000
Dec 16, 2020