Your review has been sent successfully

3S-Smart Software Solutions Update

2544
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

27 September, 2020

● Critical

2020-1843

Energy - Transportation - Manufacturing - Commercial Facilities

Description:

3S-Smart Software Solutions has released a security update to address a vulnerability in the following product:

  • CODESYS
    • CODESYS Control Runtime embedded: Versions prior to 2.3.2.8
    • CODESYS Control Runtime full: Versions prior to 2.4.7.40
    • CODESYS Control RTE: Versions prior to 2.3.7.17

Threats:

Attacker could exploit this vulnerability by doing the following:

  • Path traversal attack
  • Bypass of a protection mechanism

Best practice and Recommendations:

The CERT team encourages users to review 3S-Smart Software Solutions security advisory and apply the necessary updates:

Last updated at 27 September, 2020

Rate the content

rate-icon
up icon