An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over the runtime.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Control_for_beaglebone | Codesys | * | 3.5.13.0 (excluding) |
Control_for_empc-a/imx6 | Codesys | * | 3.5.13.0 (excluding) |
Control_for_iot2000 | Codesys | * | 3.5.13.0 (excluding) |
Control_for_pfc100 | Codesys | * | 3.5.13.0 (excluding) |
Control_for_pfc200 | Codesys | * | 3.5.13.0 (excluding) |
Control_for_raspberry_pi | Codesys | * | 3.5.13.0 (excluding) |
Control_rte | Codesys | * | 3.5.13.0 (excluding) |
Control_win | Codesys | * | 3.5.13.0 (excluding) |
Hmi | Codesys | * | 3.5.13.0 (excluding) |
Simulation_runtime | Codesys | * | 3.5.13.0 (excluding) |