← Back to browse · API

CVE-2012-6068

Severity
CRITICAL
CVSS
9.8
EPSS
0.05266
Risk score
41.04
CISA KEV
No
PoC
No
Published
2013-01-21
Modified
2025-07-02
First seen
2026-08-07
Aliases
EUVD-2012-5942, GHSA-HH9J-6V4H-23Q7
Products
3S-Smart Software Solutions:CODESYS Control RTE 0 <2.3.7.17, 3S-Smart Software Solutions:CODESYS Control Runtime embedded 0 <2.3.2.8, 3S-Smart Software Solutions:CODESYS Control Runtime full 0 <2.4.7.40, Festo:CECX-X-C1 Modular Master Controller with CoDeSys All, Festo:CECX-X-M1 Modular Controller with CoDeSys and SoftMotion All
Sources
euvd EUVD-2012-5942

Description

The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.

References