Path Validation Flaw in CODESYS Control Affects Security
CVE-2025-0694
6.6MEDIUM
What is CVE-2025-0694?
A vulnerability exists in CODESYS Control due to insufficient path validation. This flaw can allow attackers with low privileges and physical access to the system to gain unauthorized full access to the filesystem. It raises concerns regarding device security, potentially enabling unauthorized modifications and data breaches.
Affected Version(s)
CODESYS Control for BeagleBone SL 0 < 4.16.0.0
CODESYS Control for emPC-A/iMX6 SL 0 < 4.16.0.0
CODESYS Control for IOT2000 SL 0 < 4.16.0.0
References
CVSS V3.1
Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
D. Blagojevic, S.Dietz and T. Weber from CyberDanube