CVE-2012-6069
Estado: ModificadaCrítica (10)—
The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker to access files and directories outside the intended scope. This may allow an attacker to upload and download any file on the device. This could allow the attacker to affect the availability, integrity, and confidentiality of the device.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.64%
- Percentil entre todas las CVEs puntuadas: 85
- Fecha de la puntuación: 2/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-23
- CWE-22
Referencias
- http://www.codesys.com/news-events/press-releases/detail/article/sicherheitsluecke-in-codesys-v23-laufzeitsystem.html
- http://www.digitalbond.com/tools/basecamp/3s-codesys/
- https://us.codesys.com/ecosystem/security/
- https://www.cisa.gov/news-events/ics-advisories/icsa-13-011-01
- https://www.cisa.gov/news-events/ics-advisories/icsa-14-084-01
- http://ics-cert.us-cert.gov/advisories/ICSA-14-084-01
- http://www.codesys.com/news-events/press-releases/detail/article/sicherheitsluecke-in-codesys-v23-laufzeitsystem.html
- http://www.digitalbond.com/tools/basecamp/3s-codesys/
- http://www.securityfocus.com/bid/56300
- http://www.us-cert.gov/control_systems/pdf/ICSA-13-011-01.pdf
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-6069",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 10,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "3S-Smart Software Solutions",
"product": "CODESYS Control Runtime embedded",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.3.2.8",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "3S-Smart Software Solutions",
"product": "CODESYS Control Runtime full",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.4.7.40",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "3S-Smart Software Solutions",
"product": "CODESYS Control RTE",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.3.7.17",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Festo",
"product": "CECX-X-C1 Modular Master Controller with CoDeSys",
"versions": [
{
"status": "affected",
"version": "All"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Festo",
"product": "CECX-X-M1 Modular Controller with CoDeSys and SoftMotion",
"versions": [
{
"status": "affected",
"version": "All"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "3S-Smart Software Solutions",
"product": "CoDeSys",
"versions": [
{
"status": "unaffected",
"version": "3.X"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2013-01-21T21:55:01.150",
"references": [
{
"url": "http://www.codesys.com/news-events/press-releases/detail/article/sicherheitsluecke-in-codesys-v23-laufzeitsystem.html",
"tags": [
"Vendor Advisory"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "http://www.digitalbond.com/tools/basecamp/3s-codesys/",
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://us.codesys.com/ecosystem/security/",
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-13-011-01",
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-14-084-01",
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "http://ics-cert.us-cert.gov/advisories/ICSA-14-084-01",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.codesys.com/news-events/press-releases/detail/article/sicherheitsluecke-in-codesys-v23-laufzeitsystem.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.digitalbond.com/tools/basecamp/3s-codesys/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/56300",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.us-cert.gov/control_systems/pdf/ICSA-13-011-01.pdf",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"description": [
{
"lang": "en",
"value": "CWE-23"
}
]
},
{
"type": "Secondary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The CoDeSys Runtime Toolkit’s file transfer functionality does not \nperform input validation, which allows an attacker to access files and \ndirectories outside the intended scope. This may allow an attacker to \nupload and download any file on the device. This could allow the \nattacker to affect the availability, integrity, and confidentiality of \nthe device."
},
{
"lang": "es",
"value": "Vulnerabilidad de salto de directorio en el Runtime Toolkit de CODESYS Runtime System v2.3.x y v2.4.x que permite a atacantes remotos leer, sobreescribir, o crear ficheros a través de .. (punto punto) en una solicitud al servicio de escucha TCP."
}
],
"lastModified": "2026-06-16T23:47:45.993",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:3s-software:codesys_runtime_system:2.4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89253C44-34F0-457C-9EEE-E7028F737E02"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:3s-software:codesys_runtime_system:2.3.9.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CFAB8128-4A70-44CA-A4D3-C859010C8BFF"
},
{
"criteria": "cpe:2.3:a:3s-software:codesys_runtime_system:2.3.9.35:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B99BA40-647D-4203-A003-CAEEF776EF77"
},
{
"criteria": "cpe:2.3:a:3s-software:codesys_runtime_system:2.3.9.36:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "50443443-14B4-4245-BBE3-C5E451739EF0"
},
{
"criteria": "cpe:2.3:a:3s-software:codesys_runtime_system:2.3.9.37:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "44C690B5-EE5B-4504-B40D-879F757C8029"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}