Записи 3s-software
13 опубликованных записей вендора 3s-software.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 7,7 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-287 Improper Authentication2
- CWE-121 Stack-based Buffer Overflow1
- CWE-189 Numeric Errors1
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-23 Relative Path Traversal1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
59В плане | CVE-2012-4705Готовый эксплойт | Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors3s-software · codesys gateway-server · CWE-22 | Критическая10,0 | — | 64,9 % | 24 февр. 2013 г. |
42В плане | CVE-2012-4708Эксплойта нет | Stack-based buffer overflow in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted pac3s-software · codesys gateway-server · CWE-119 | Критическая10,0 | — | 7,4 % | 24 февр. 2013 г. |
41В плане | CVE-2012-6068Эксплойта нет | 3S CoDeSys Improper Access Control3s-software · codesys runtime system · CWE-284 | Критическая9,8 | — | 5,3 % | 21 янв. 2013 г. |
41В плане | CVE-2012-4704Эксплойта нет | Array index error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet.3s-software · codesys gateway-server · CWE-20 | Критическая10,0 | — | 4,2 % | 24 февр. 2013 г. |
41В плане | CVE-2013-2781Эксплойта нет | Use-after-free vulnerability in the server application in 3S CODESYS Gateway 2.3.9.27 allows remote attackers to cause a denial of service (3s-software · codesys gateway-server · CWE-399 | Критическая10,0 | — | 3,8 % | 23 мая 2013 г. |
41В плане | CVE-2012-4707Эксплойта нет | 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors that trigger an out-of-bounds memory3s-software · codesys gateway-server · CWE-94 | Критическая10,0 | — | 3,6 % | 24 февр. 2013 г. |
41В плане | CVE-2012-6069Эксплойта нет | 3S CoDeSys Relative Path Traversal3s-software · codesys runtime system · CWE-23 | Критическая10,0 | — | 2,6 % | 21 янв. 2013 г. |
40В плане | CVE-2018-5440Эксплойта нет | A Stack-based Buffer Overflow issue was discovered in 3S-Smart CODESYS Web Server.3s-software · codesys runtime system · CWE-121 | Критическая9,8 | — | 3,1 % | 15 февр. 2018 г. |
38Наблюдать | CVE-2014-0760Эксплойта нет | Festo CECX-X-(C1/M1) Controller Improper Authenticationfesto · cecx-x-c1 modular master controller · CWE-287 | Критическая9,3 | — | 3,3 % | 25 апр. 2014 г. |
38Наблюдать | CVE-2014-0769Эксплойта нет | Festo CECX-X-(C1/M1) Controller Improper Authenticationfesto · cecx-x-m1 modular controller · CWE-287 | Критическая9,3 | — | 2,3 % | 25 апр. 2014 г. |
31Наблюдать | CVE-2012-4706Эксплойта нет | Integer signedness error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to cause a denial of service via a crafted pac3s-software · codesys gateway-server · CWE-189 | Высокая7,8 | — | 1,6 % | 24 февр. 2013 г. |
21Наблюдать | CVE-2014-0757Эксплойта нет | Smart Software Solutions (3S) CoDeSys Runtime Toolkit NULL Pointer Dereference3s-software · codesys runtime toolkit · CWE-476 | Средняя5,0 | — | 3,2 % | 31 янв. 2014 г. |
21Наблюдать | CVE-2015-6482Эксплойта нет | Runtime Toolkit before 2.4.7.48 in 3S-Smart CODESYS before 2.3.9.48 allows remote attackers to cause a denial of service (NULL pointer deref3s-software · codesys runtime system | Средняя5,0 | — | 2,1 % | 18 окт. 2015 г. |
- CVE-2012-470559В плане
Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors
КритическаяCVSS 10,0Готовый эксплойтEPSS 65 %3s-software · codesys gateway-server24 февр. 2013 г.
- CVE-2012-470842В плане
Stack-based buffer overflow in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted pac
КритическаяCVSS 10,0Эксплойта нетEPSS 7 %3s-software · codesys gateway-server24 февр. 2013 г.
- CVE-2012-606841В плане
3S CoDeSys Improper Access Control
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %3s-software · codesys runtime system21 янв. 2013 г.
- CVE-2012-470441В плане
Array index error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet.
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %3s-software · codesys gateway-server24 февр. 2013 г.
- CVE-2013-278141В плане
Use-after-free vulnerability in the server application in 3S CODESYS Gateway 2.3.9.27 allows remote attackers to cause a denial of service (
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %3s-software · codesys gateway-server23 мая 2013 г.
- CVE-2012-470741В плане
3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors that trigger an out-of-bounds memory
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %3s-software · codesys gateway-server24 февр. 2013 г.
- CVE-2012-606941В плане
3S CoDeSys Relative Path Traversal
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %3s-software · codesys runtime system21 янв. 2013 г.
- CVE-2018-544040В плане
A Stack-based Buffer Overflow issue was discovered in 3S-Smart CODESYS Web Server.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %3s-software · codesys runtime system15 февр. 2018 г.
- CVE-2014-076038Наблюдать
Festo CECX-X-(C1/M1) Controller Improper Authentication
КритическаяCVSS 9,3Эксплойта нетEPSS 3 %festo · cecx-x-c1 modular master controller25 апр. 2014 г.
- CVE-2014-076938Наблюдать
Festo CECX-X-(C1/M1) Controller Improper Authentication
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %festo · cecx-x-m1 modular controller25 апр. 2014 г.
- CVE-2012-470631Наблюдать
Integer signedness error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to cause a denial of service via a crafted pac
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %3s-software · codesys gateway-server24 февр. 2013 г.
- CVE-2014-075721Наблюдать
Smart Software Solutions (3S) CoDeSys Runtime Toolkit NULL Pointer Dereference
СредняяCVSS 5,0Эксплойта нетEPSS 3 %3s-software · codesys runtime toolkit31 янв. 2014 г.
- CVE-2015-648221Наблюдать
Runtime Toolkit before 2.4.7.48 in 3S-Smart CODESYS before 2.3.9.48 allows remote attackers to cause a denial of service (NULL pointer deref
СредняяCVSS 5,0Эксплойта нетEPSS 2 %3s-software · codesys runtime system18 окт. 2015 г.