Buffer Size Calculation Vulnerability Leads to DoS in CODESYS Products
CVE-2024-5000

7.5HIGH

What is CVE-2024-5000?

The vulnerability arises from a flaw in the handling of requests sent by an unauthenticated remote attacker using a malicious OPC UA client. When the crafted request is processed, it can trigger a denial of service (DoS) condition due to improper buffer size calculations within the affected CODESYS products. This can lead to service disruptions and impact the operational integrity of systems relying on the CODESYS Automation Platform.

Affected Version(s)

CODESYS Control for BeagleBone SL 0 < 4.12.0.0

CODESYS Control for emPC-A/iMX6 SL 0 < 4.12.0.0

CODESYS Control for IOT2000 SL 0 < 4.12.0.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ABB Schweiz AG.
.
CVE-2024-5000 : Buffer Size Calculation Vulnerability Leads to DoS in CODESYS Products