10

CVE-2018-10612

In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CodesysControl For Beaglebone Sl Version >= 3.0 < 3.5.14.0
CodesysControl For Empc-a/imx6 Sl Version >= 3.0 < 3.5.14.0
CodesysControl For Iot2000 Sl Version >= 3.0 < 3.5.14.0
CodesysControl For Linux Sl Version >= 3.0 < 3.5.14.0
CodesysControl For Pfc100 Sl Version >= 3.0 < 3.5.14.0
CodesysControl For Pfc200 Sl Version >= 3.0 < 3.5.14.0
CodesysControl For Raspberry Pi Sl Version >= 3.0 < 3.5.14.0
CodesysControl Rte Sl Version >= 3.0 < 3.5.14.0
CodesysControl Runtime Toolkit Version >= 3.0 < 3.5.14.0
CodesysControl Win Sl Version >= 3.0 < 3.5.14.0
CodesysDevelopment System V3 Version >= 3.0 < 3.5.14.0
CodesysHmi Sl Version >= 3.0 < 3.5.14.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.31
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CWE-311 Missing Encryption of Sensitive Data

The product does not encrypt sensitive or critical information before storage or transmission.

CWE-732 Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.