CVE detail
CVE-2012-6068 — CVE-2012-6068
Published 2013-01-21 · Modified 2026-06-16 · Vendor 3s-software · Product codesys_runtime_system · Source nvd
CRITICAL
severity
CVSS-derived band
0.0527
EPSS probability
exploitation probability, 30d
92.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References