CVE-2019-9012 describes a denial-of-service vulnerability in 3S-Smart CODESYS V3 products, affecting all variants prior to v3.5.14.20 that contain the CmpGateway component, including various CODESYS Control and Development System products. A crafted communication request can lead to uncontrolled memory allocations, causing a system crash. With a CVSS score of 7.5 (HIGH), this vulnerability is remotely exploitable with low attack complexity and no user interaction required, resulting in high availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion beyond a single mention related to a broader advisory.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0, < 3.5.14.20CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:* | ||
>= 3.0, < 3.5.14.20CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:* | ||
>= 3.0, < 3.5.14.20CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:* | ||
>= 3.0, < 3.5.14.20CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:* | ||
>= 3.0, < 3.5.14.20CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple Vulnerabilities in 3S CODESYS Runtime in Rexroth PRC7000
Dec 16, 2020Multiple Vulnerabilities in 3S CODESYS Runtime in Rexroth PRC7000
Dec 16, 2020Multiple Vulnerabilities in 3S CODESYS Runtime in Rexroth PRC7000
Dec 16, 2020Multiple Vulnerabilities in 3S CODESYS Runtime in Rexroth PRC7000
Dec 16, 2020Multiple Vulnerabilities in 3S CODESYS Runtime in Rexroth PRC7000
Dec 16, 2020