Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-7052

19
FAUCET Score

CVE-2020-7052 is a denial-of-service vulnerability affecting CODESYS Control V3, Gateway V3, and HMI V3 versions prior to 3.5.15.30. This medium-severity flaw (CVSS 6.5) allows a remote, low-privileged attacker to cause a system crash by triggering uncontrolled memory allocation. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community discussion, indicating awareness within the cybersecurity community.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.5.15.30CPE matchmatch criteria
cpe:2.3:a:codesys:control_for_beaglebone:*:*:*:*:*:*:*:*
< 3.5.15.30CPE matchmatch criteria
cpe:2.3:a:codesys:control_for_empc-a\/imx6:*:*:*:*:*:*:*:*
< 3.5.15.30CPE matchmatch criteria
cpe:2.3:a:codesys:control_for_iot2000:*:*:*:*:*:*:*:*
< 3.5.15.30CPE matchmatch criteria
cpe:2.3:a:codesys:control_for_linux:*:*:*:*:*:*:*:*
< 3.5.15.30CPE matchmatch criteria
cpe:2.3:a:codesys:control_for_pfc100:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.88%
Probability of exploitation in next 30 days
EPSS Percentile
77.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0188 is in the 90th percentile among its peer group of 21,951 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (11)

amazonvendor investigatingvia llm_extracted
apollographqlvendor investigatingvia llm_extracted
boschvendor investigatingvia llm_extracted
dfinityvendor investigatingvia llm_extracted
fleetdmvendor investigatingvia llm_extracted
mathworksvendor investigatingvia llm_extracted
maxkbvendor investigatingvia llm_extracted
nxpvendor investigatingvia llm_extracted
openfirevendor investigatingvia llm_extracted
openstackvendor investigatingvia llm_extracted
opnsensevendor investigatingvia llm_extracted

Vendor Advisories (11)

fleetdmllm-fleetdm-0cffa175819eb60fHIGH

Denial of Service in PLC Runtime affecting Rexroth IndraMotion Products

Dec 16, 2020
amazonllm-amazon-a8a30150585d5212HIGH

Denial of Service in PLC Runtime affecting Rexroth IndraMotion Products

Dec 16, 2020
apollographqlllm-apollographql-aa28000fa0174283HIGH

Denial of Service in PLC Runtime affecting Rexroth IndraMotion Products

Dec 16, 2020
dfinityllm-dfinity-a05cc178c91490e1HIGH

Denial of Service in PLC Runtime affecting Rexroth IndraMotion Products

Dec 16, 2020
mathworksllm-mathworks-826b7e1e0214b5c7HIGH

Denial of Service in PLC Runtime affecting Rexroth IndraMotion Products

Dec 16, 2020
maxkbllm-maxkb-86f0ca01f37f66acHIGH

CODESYS V3 Denial of Service

Jan 23, 2020
openstackllm-openstack-94d6a62003f315f2HIGH

CODESYS V3 Denial of Service

Jan 23, 2020
nxpllm-nxp-1d5fb99045f61107HIGH

CODESYS V3 Denial of Service

Jan 23, 2020
openfirellm-openfire-ca198f889e02fe4bHIGH

CODESYS V3 Denial of Service

Jan 23, 2020
opnsensellm-opnsense-57b919464f0ec5efHIGH

CODESYS V3 Denial of Service

Jan 23, 2020
boschllm-bosch-e8093ce8dafc96aeHIGH

CODESYS V3 Denial of Service

Jan 23, 2020

References

customers.codesys.com / index.php
Vendor Advisory
tenable.com / security/research/tra-2020-04
ExploitThird Party Advisory