Description
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.
Published: 2019-09-13
Score: 7.5 High
EPSS: 1.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-4987 CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.
History

No history.

Subscriptions

Codesys Control For Beaglebone Control For Empc-a\/imx6 Control For Iot2000 Control For Linux Control For Pfc100 Control For Pfc200 Control For Raspberry Pi Control Rte Control Runtime System Toolkit Control Win Embedded Target Visu Toolkit Hmi Remote Target Visu Toolkit
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-04T23:57:39.525Z

Reserved: 2019-07-11T00:00:00.000Z

Link: CVE-2019-13532

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-09-13T17:15:11.617

Modified: 2024-11-21T04:25:05.470

Link: CVE-2019-13532

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses