peter bassill · operator
$ cve CVE-2012-6068 JSON

CVE-2012-6068

9.8
CRITICAL · CVSS 3.1 · EPSS 5.3% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.27% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-284
On CISA KEVno
Public exploitnone known
Published2013-01-21
Last modified2026-06-16

Affected (1)

VendorProduct
3s-softwarecodesys runtime system

References

→ the Explorer  ·  watch your stack  ·  NVD