Improper access control in CODESYS Control for BeagleBone and CODESYS Control RTE - CVE-2018-10612
Published: December 18, 2018 / Updated: December 19, 2018
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions the target system.
The vulnerability exists due to user access management and communication encryption is not enabled by default. A remote unauthenticated attacker can gain access to the device and sensitive information, including user credentials.
Affected software
CODESYS Control RTE
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Opensuse