6.5

CVE-2020-12068

An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Codesys ≫ Control For Beaglebone Version < 3.5.16.0
Codesys ≫ Control For Empc-a/imx6 Version < 3.5.16.0
Codesys ≫ Control For Iot2000 Version < 3.5.16.0
Codesys ≫ Control For Pfc100 Version < 3.5.16.0
Codesys ≫ Control For Pfc200 Version < 3.5.16.0
Codesys ≫ Control For Plcnext Version < 3.5.16.0
Codesys ≫ Control For Raspberry Pi Version < 3.5.16.0
Codesys ≫ Control Rte Version >= 3.0 < 3.5.16.0
Codesys ≫ Control Runtime System Toolkit Version >= 3.0 < 3.5.16.0
Codesys ≫ Control Win Version >= 3.0 < 3.5.16.0
Codesys ≫ Development System Version < 3.5.16.0
Codesys ≫ Hmi Version >= 3.0 < 3.5.16.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.92% 0.555
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://www.codesys.com
Product
https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=13136&token=c267875c01ea70bc9613bc39c684eedc17f55420&download=
Vendor Advisory
Mitigation