Codesys Runtime Improper Limitation of a Pathname
CVE-2018-25048
8.8HIGH
What is CVE-2018-25048?
The CODESYS runtime system in multiple versions contains a path traversal vulnerability that enables a remote attacker with low privileges to gain access to and modify sensitive system files. This vulnerability could potentially lead to a denial-of-service condition, compromising the integrity and availability of the device.
Affected Version(s)
Control for emPC-A/iMX6 3.0.0.0 < 3.5.12.30
Control for BeagleBone 3.0.0.0 < 3.5.12.30
Control for IOT2000 3.0.0.0 < 3.5.12.30