CVE Feed

    Dashboard / CVE / CVE-2012-6069

    CVE-2012-6069

    The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker to access files and directories outside the intended scope. This may allow an attacker to upload and download any file on the device. This could allow the attacker to affect the availability, integrity, and confidentiality of the device.

    Published:Jan 21, 2013
    Last Modified:Jul 2, 2025
    EPS:Jan 21, 2013
    EPSS Score:0.02234
    CVSS Score:10

    Affected Products

    Vendor
    3s-software
    Product
    Codesys Runtime System

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High