Communication Channel Ownership Vulnerability in CODESYS V3 Products by 3S-Smart
CVE-2019-9010

9.8CRITICAL

What is CVE-2019-9010?

An authentication oversight exists in 3S-Smart's CODESYS V3 products, wherein the CODESYS Gateway fails to properly verify the ownership of communication channels. This vulnerability affects all versions prior to v3.5.14.20 of various CODESYS V3 products, regardless of the CPU type or operating system, including CODESYS Control for multiple platforms. This flaw can potentially compromise the integrity of communication within industrial control systems, making it imperative for users to update to the latest versions to mitigate risks.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-9010 : Communication Channel Ownership Vulnerability in CODESYS V3 Products by 3S-Smart