Improper access control in CODESYS Control for BeagleBone and CODESYS Control RTE - CVE-2018-10612

 

Improper access control in CODESYS Control for BeagleBone and CODESYS Control RTE - CVE-2018-10612

Published: December 18, 2018 / Updated: December 19, 2018


Vulnerability identifier: #VU16612
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10612
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions the target system.

The vulnerability exists due to user access management and communication encryption is not enabled by default. A remote unauthenticated attacker can gain access to the device and sensitive information, including user credentials.


Affected software

CODESYS Control for BeagleBone
CODESYS Control RTE

Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Opensuse

How to mitigate CVE-2018-10612

Update the affected products to the version 3.5.14.0.


External References

Related Security Bulletins