3S-Smart Software Solutions Update
2544Warning Date
Severity Level
Warning Number
Target Sector
27 September, 2020
● Critical
2020-1843
Energy - Transportation - Manufacturing - Commercial Facilities
Description:
3S-Smart Software Solutions has released a security update to address a vulnerability in the following product:
- CODESYS
- CODESYS Control Runtime embedded: Versions prior to 2.3.2.8
- CODESYS Control Runtime full: Versions prior to 2.4.7.40
- CODESYS Control RTE: Versions prior to 2.3.7.17
Threats:
Attacker could exploit this vulnerability by doing the following:
- Path traversal attack
- Bypass of a protection mechanism
Best practice and Recommendations:
The CERT team encourages users to review 3S-Smart Software Solutions security advisory and apply the necessary updates: