Resource exhaustion in CODESYS products - CVE-2020-7052
Published: January 31, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to uncontrolled memory allocation in affected products containing communication servers for the CODESYS communication protocol. A remote authenticated attacker can send a specially crafted request, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
CODESYS Control for emPC-A/iMX6
CODESYS Control for IOT2000
CODESYS Control for Linux
CODESYS Control for PLCnext
CODESYS Control for PFC100
CODESYS Control for PFC200
CODESYS Control for Raspberry Pi
CODESYS Control RTE V3
CODESYS Control RTE V3 (for Beckhoff CX)
CODESYS Control Win V3 (part of the CODESYS Development System setup)
CODESYS Control V3 Runtime System Toolkit
CODESYS V3 Safety SIL2
CODESYS Gateway V3
CODESYS HMI V3
CODESYS V3 Simulation Runtime (part of the CODESYS Development System)
How to mitigate CVE-2020-7052
CODESYS Control for emPC-A/iMX6 - update to 3.5.15.30
CODESYS Control for IOT2000 - update to 3.5.15.30
CODESYS Control for Linux - update to 3.5.15.30
CODESYS Control for PLCnext - update to 3.5.15.30
CODESYS Control for PFC100 - update to 3.5.15.30
CODESYS Control for PFC200 - update to 3.5.15.30
CODESYS Control for Raspberry Pi - update to 3.5.15.30
CODESYS Control RTE V3 - update to 3.5.15.30
CODESYS Control RTE V3 (for Beckhoff CX) - update to 3.5.15.30
CODESYS Control Win V3 (part of the CODESYS Development System setup) - update to 3.5.15.30
CODESYS Control V3 Runtime System Toolkit - update to 3.5.15.30
CODESYS V3 Safety SIL2 - update to 3.5.15.30
CODESYS Gateway V3 - update to 3.5.15.30
CODESYS HMI V3 - update to 3.5.15.30
CODESYS V3 Simulation Runtime (part of the CODESYS Development System) - update to 3.5.15.30