Back

CRITICAL

3S CoDeSys Relative Path Traversal

Published Jan 21, 2013

Description

The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker to access files and directories outside the intended scope. This may allow an attacker to upload and download any file on the device. This could allow the attacker to affect the availability, integrity, and confidentiality of the device.

Affected products

Remediation

Vendor solution

CoDeSys recommends upgrading to the latest version, which is Version 3. It can be downloaded here https://store.codesys.com/engineering/codesys.html .3S released a patch which implements a password for authentication to the device.

The patch can be downloaded from the CoDeSys Download Center http://www.codesys.com/download.html .

CoDeSys Version 3.X is not affected by these vulnerabilities.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Jan 21, 2013
Updated Jul 2, 2025
Reserved Dec 5, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a