Use of insufficiently random values in CODESYS products - CVE-2018-20025

 

Use of insufficiently random values in CODESYS products - CVE-2018-20025

Published: December 18, 2018 / Updated: December 19, 2018


Vulnerability identifier: #VU16610
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-20025
CWE-ID: CWE-330
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The vulnerability exists due to weak random values. A remote unauthenticated attacker can bypass security restrictions to affect the confidentiality and integrity of data stored on the device.


Affected software

CODESYS Control Runtime System Toolkit
CODESYS Control for BeagleBone
CODESYS Control for emPC-A/iMX6
CODESYS Control for IOT2000
CODESYS Control for Linux
CODESYS Control for PFC100
CODESYS Control for PFC200
CODESYS Control for Raspberry Pi
CODESYS Control RTE
CODESYS Control Win
CODESYS Simulation Runtime
CODESYS Embedded Target Visu Toolkit
CODESYS Remote Target Visu Toolkit
CODESYS Safety SIL2
CODESYS Gateway
CODESYS HMI
CODESYS OPC Server
CODESYS PLCHandler SDK
CODESYS Development System

How to mitigate CVE-2018-20025

Install update from vendor's website.


External References

Related Security Bulletins