CVE-2019-9009
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/09/2019
Last modified:
17/06/2026
Description
An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:codesys:control_for_beaglebone:*:*:*:*:*:*:*:* | 3.5.15.0 (excluding) | |
| cpe:2.3:a:codesys:control_for_empc-a\/imx6:*:*:*:*:*:*:*:* | 3.5.15.0 (excluding) | |
| cpe:2.3:a:codesys:control_for_iot2000:*:*:*:*:*:*:*:* | 3.5.15.0 (excluding) | |
| cpe:2.3:a:codesys:control_for_pfc100:*:*:*:*:*:*:*:* | 3.5.15.0 (excluding) | |
| cpe:2.3:a:codesys:control_for_pfc200:*:*:*:*:*:*:*:* | 3.5.15.0 (excluding) | |
| cpe:2.3:a:codesys:control_for_raspberry_pi:*:*:*:*:*:*:*:* | 3.5.15.0 (excluding) | |
| cpe:2.3:a:codesys:control_rte:*:*:*:*:*:*:*:* | 3.5.15.0 (excluding) | |
| cpe:2.3:a:codesys:control_win:*:*:*:*:*:*:*:* | 3.5.15.0 (excluding) | |
| cpe:2.3:a:codesys:gateway:*:*:*:*:*:*:*:* | 3.5.15.0 (excluding) | |
| cpe:2.3:a:codesys:hmi:*:*:*:*:*:*:*:* | 3.5.15.0 (excluding) | |
| cpe:2.3:a:codesys:linux:*:*:*:*:*:*:*:* | 3.5.15.0 (excluding) | |
| cpe:2.3:a:codesys:runtime_system_toolkit:*:*:*:*:*:*:*:* | 3.5.15.0 (excluding) | |
| cpe:2.3:a:codesys:safety_sil2:*:*:*:*:*:*:*:* | 3.5.15.0 (excluding) | |
| cpe:2.3:a:codesys:simulation_runtime:*:*:*:*:*:*:*:* | 3.5.15.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=12941&token=50fabe3870c7bdc41701eb1799dddeec103de40c&download=
- https://www.us-cert.gov/ics/advisories/icsa-19-255-05
- https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=12941&token=50fabe3870c7bdc41701eb1799dddeec103de40c&download=
- https://www.us-cert.gov/ics/advisories/icsa-19-255-05



