← Back to browse · API

CVE-2012-6069

Severity
CRITICAL
CVSS
10.0
EPSS
0.02637
Risk score
40.92
CISA KEV
No
PoC
No
Published
2013-01-21
Modified
2025-07-02
First seen
2026-08-07
Aliases
EUVD-2012-5943, GHSA-6Q9J-3828-RFXJ
Products
3S-Smart Software Solutions:CODESYS Control RTE 0 <2.3.7.17, 3S-Smart Software Solutions:CODESYS Control Runtime embedded 0 <2.3.2.8, 3S-Smart Software Solutions:CODESYS Control Runtime full 0 <2.4.7.40, Festo:CECX-X-C1 Modular Master Controller with CoDeSys All, Festo:CECX-X-M1 Modular Controller with CoDeSys and SoftMotion All
Sources
euvd EUVD-2012-5943

Description

The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker to access files and directories outside the intended scope. This may allow an attacker to upload and download any file on the device. This could allow the attacker to affect the availability, integrity, and confidentiality of the device.

References