An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the following CODESYS V3 products in all versions containing the CmpUserMgr component are affected regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS V3 Simulation Runtime (part of the CODESYS Development System), CODESYS Control V3 Runtime System Toolkit, CODESYS HMI V3.
References
Link | Resource |
---|---|
https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=12943&token=d097958a67ba382de688916f77e3013c0802fade&download= | Vendor Advisory |
https://www.us-cert.gov/ics/advisories/icsa-19-213-04 | Third Party Advisory US Government Resource |
https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=12943&token=d097958a67ba382de688916f77e3013c0802fade&download= | Vendor Advisory |
https://www.us-cert.gov/ics/advisories/icsa-19-213-04 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:50
Type | Values Removed | Values Added |
---|---|---|
References | () https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=12943&token=d097958a67ba382de688916f77e3013c0802fade&download= - Vendor Advisory | |
References | () https://www.us-cert.gov/ics/advisories/icsa-19-213-04 - Third Party Advisory, US Government Resource |
Information
Published : 2019-08-15 17:15
Updated : 2024-11-21 04:50
NVD link : CVE-2019-9013
Mitre link : CVE-2019-9013
CVE.ORG link : CVE-2019-9013
JSON object : View
Products Affected
codesys
- control_for_empc-a\/imx6_sl
- control_for_pfc100_sl
- control_for_linux_sl
- control_rte_sl
- hmi_sl
- raspberry_pi
- control_for_pfc200_sl
- control_for_iot2000_sl
- development_system
- runtime_toolkit
- control_for_beaglebone_sl
- control_win_sl
CWE
CWE-327
Use of a Broken or Risky Cryptographic Algorithm