CVE-2012-6069

critical

Description

The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker to access files and directories outside the intended scope. This may allow an attacker to upload and download any file on the device. This could allow the attacker to affect the availability, integrity, and confidentiality of the device.

References

https://www.cisa.gov/news-events/ics-advisories/icsa-14-084-01

https://www.cisa.gov/news-events/ics-advisories/icsa-13-011-01

https://us.codesys.com/ecosystem/security/

http://www.us-cert.gov/control_systems/pdf/ICSA-13-011-01.pdf

http://www.securityfocus.com/bid/56300

http://www.digitalbond.com/tools/basecamp/3s-codesys/

http://www.codesys.com/news-events/press-releases/detail/article/sicherheitsluecke-in-codesys-v23-laufzeitsystem.html

http://ics-cert.us-cert.gov/advisories/ICSA-14-084-01

Details

Source: Mitre, NVD

Published: 2013-01-21

Updated: 2025-07-02

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 10

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00983