The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including those with higher privileges.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| CODESYS | CODESYS Control RTE (SL) | >= 3.0.0.0, < 3.5.22.20CNA affecteddefault unaffected | |
| CODESYS | CODESYS Control RTE (For Beckhoff CX) SL | >= 3.0.0.0, < 3.5.22.20CNA affecteddefault unaffected | |
| CODESYS | CODESYS Control Win (SL) | >= 3.0.0.0, < 3.5.22.20CNA affecteddefault unaffected | |
| CODESYS | CODESYS Control For BeagleBone SL | >= 3.0.0.0, < 4.21.0.0CNA affecteddefault unaffected | |
| CODESYS | CODESYS Control For IOT2000 SL | >= 3.0.0.0, < 4.21.0.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.