An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed, this results in a crash.
📦
control_for_wago_touch_panels_600_sl
Vendor: codesys
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
13
Remote Access
Total CVEs
44
Total Indexed
Avg. EPSS
0.93%
Exploit Prob.
Security Vulnerability Index
Page 5 / 5
7.1
CVSS
Severity: HIGH
6.5
CVSS
An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.
Severity: MEDIUM
7.3
CVSS
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.
Severity: HIGH