CVE Feed

    Dashboard / CVE / CVE-2019-9013

    CVE-2019-9013

    An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the following CODESYS V3 products in all versions containing the CmpUserMgr component are affected regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS V3 Simulation Runtime (part of the CODESYS Development System), CODESYS Control V3 Runtime System Toolkit, CODESYS HMI V3.

    Published:Aug 15, 2019
    Last Modified:Nov 21, 2024
    EPS:Aug 15, 2019
    EPSS Score:0.0018
    CVSS Score:8.8

    Affected Products

    Vendor
    Codesys
    Product
    Control For Beaglebone Sl
    Vendor
    Codesys
    Product
    Control For Empc-a\/imx6 Sl
    Vendor
    Codesys
    Product
    Control For Iot2000 Sl
    Vendor
    Codesys
    Product
    Control For Linux Sl
    Vendor
    Codesys
    Product
    Control For Pfc100 Sl
    Vendor
    Codesys
    Product
    Control For Pfc200 Sl
    Vendor
    Codesys
    Product
    Control Rte Sl
    Vendor
    Codesys
    Product
    Control Win Sl
    Vendor
    Codesys
    Product
    Development System
    Vendor
    Codesys
    Product
    Hmi Sl
    Vendor
    Codesys
    Product
    Raspberry Pi
    Vendor
    Codesys
    Product
    Runtime Toolkit

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High