TROYANOSYVIRUS
Volver a CVEs

CVE-2019-13532

HIGH
7.5

Descripcion

CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.

Detalles CVE

Puntuacion CVSS v3.17.5
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado9/13/2019
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0

Productos afectados

codesys:control_for_beaglebonecodesys:control_for_empc-a\/imx6codesys:control_for_iot2000codesys:control_for_linuxcodesys:control_for_pfc100codesys:control_for_pfc200codesys:control_for_raspberry_picodesys:control_rtecodesys:control_runtime_system_toolkitcodesys:control_wincodesys:embedded_target_visu_toolkitcodesys:hmicodesys:remote_target_visu_toolkit

Debilidades (CWE)

CWE-22CWE-22

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.