Remote Code Execution Vulnerability in CODESYS Runtime by 3S-Smart Software Solutions
CVE-2020-6081

9.9CRITICAL

Key Information:

Vendor

Codesys

Status
Vendor
CVE Published:
7 May 2020

What is CVE-2020-6081?

A vulnerability exists in the PLC_Task functionality of CODESYS Runtime that allows remote code execution. By sending a specially crafted network request, an attacker can exploit this weakness to execute arbitrary code on the affected system. This can potentially lead to unauthorized control and manipulation of the system's operations, posing significant risks to industrial automation and control environments.

Affected Version(s)

3S 3S-Smart Software Solutions GmbH CODESYS Runtime 3.5.14.30

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-6081 : Remote Code Execution Vulnerability in CODESYS Runtime by 3S-Smart Software Solutions