CODESYS
CODESYS Control V3 Removable Media Path Vulnerability Advisory
Pages
5
Time to read
7 mins
Publication
Language
English
Pages
5
Time to read
7 mins
Publication
Language
English
This document is a security advisory detailing a vulnerability in the CODESYS Control V3 runtime system related to removable media path traversal. It describes how a low privileged attacker with physical access to a controller can exploit insufficient path validation by using removable media that supports symbolic links. This exploitation can lead to unauthorized access to the entire file system. The advisory lists affected products and specifies versions that are vulnerable. It also provides identifiers for the vulnerability, including CVE and CWE references, and a CVSS score indicating the severity level. The document outlines the impact of the vulnerability, explaining how it can be exploited under specific conditions, and provides remediation steps, including necessary updates to various CODESYS Control products. Additionally, it offers mitigation strategies and general security recommendations to enhance protection against such vulnerabilities.