CVE Vulnerabilities

CVE-2020-12068

Published: May 14, 2020 | Modified: Jul 21, 2021
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.

Affected Software

Name Vendor Start Version End Version
Control_for_beaglebone Codesys * 3.5.16.0 (excluding)
Control_for_empc-a/imx6 Codesys * 3.5.16.0 (excluding)
Control_for_iot2000 Codesys * 3.5.16.0 (excluding)
Control_for_pfc100 Codesys * 3.5.16.0 (excluding)
Control_for_pfc200 Codesys * 3.5.16.0 (excluding)
Control_for_plcnext Codesys * 3.5.16.0 (excluding)
Control_for_raspberry_pi Codesys * 3.5.16.0 (excluding)
Control_rte Codesys 3.0 (including) 3.5.16.0 (excluding)
Control_runtime_system_toolkit Codesys 3.0 (including) 3.5.16.0 (excluding)
Control_win Codesys 3.0 (including) 3.5.16.0 (excluding)
Development_system Codesys * 3.5.16.0 (excluding)
Hmi Codesys 3.0 (including) 3.5.16.0 (excluding)

References