CODESYS SP Realtime NT Vulnerability in 3S-Smart Products
CVE-2019-19789

6.5MEDIUM

Key Information:

Vendor

Codesys

Vendor
CVE Published:
20 December 2019

What is CVE-2019-19789?

The vulnerability in 3S-Smart CODESYS products allows a NULL pointer dereference, potentially leading to system crashes or unexpected behavior. Affected versions include CODESYS SP Realtime NT prior to V2.3.7.28, CODESYS Runtime Toolkit 32 bit full prior to V2.4.7.54, and CODESYS PLCWinNT prior to V2.4.7.54. Users are encouraged to update to the latest versions to mitigate potential security risks. For further details, visit the official CODESYS website and review the provided resources.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.