3s-software records
13 published records for vendor 3s-software.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 7.7%
- Pre-auth RCE
- 7
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication2
- CWE-121 Stack-based Buffer Overflow1
- CWE-189 Numeric Errors1
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-23 Relative Path Traversal1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
59Plan | CVE-2012-4705Weaponized | Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors3s-software · codesys gateway-server · CWE-22 | Critical10.0 | — | 64.9% | Feb 24, 2013 |
42Plan | CVE-2012-4708No exploit | Stack-based buffer overflow in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted pac3s-software · codesys gateway-server · CWE-119 | Critical10.0 | — | 7.4% | Feb 24, 2013 |
41Plan | CVE-2012-6068No exploit | 3S CoDeSys Improper Access Control3s-software · codesys runtime system · CWE-284 | Critical9.8 | — | 5.3% | Jan 21, 2013 |
41Plan | CVE-2012-4704No exploit | Array index error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet.3s-software · codesys gateway-server · CWE-20 | Critical10.0 | — | 4.2% | Feb 24, 2013 |
41Plan | CVE-2013-2781No exploit | Use-after-free vulnerability in the server application in 3S CODESYS Gateway 2.3.9.27 allows remote attackers to cause a denial of service (3s-software · codesys gateway-server · CWE-399 | Critical10.0 | — | 3.8% | May 23, 2013 |
41Plan | CVE-2012-4707No exploit | 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors that trigger an out-of-bounds memory3s-software · codesys gateway-server · CWE-94 | Critical10.0 | — | 3.6% | Feb 24, 2013 |
41Plan | CVE-2012-6069No exploit | 3S CoDeSys Relative Path Traversal3s-software · codesys runtime system · CWE-23 | Critical10.0 | — | 2.6% | Jan 21, 2013 |
40Plan | CVE-2018-5440No exploit | A Stack-based Buffer Overflow issue was discovered in 3S-Smart CODESYS Web Server.3s-software · codesys runtime system · CWE-121 | Critical9.8 | — | 3.1% | Feb 15, 2018 |
38Monitor | CVE-2014-0760No exploit | Festo CECX-X-(C1/M1) Controller Improper Authenticationfesto · cecx-x-c1 modular master controller · CWE-287 | Critical9.3 | — | 3.3% | Apr 25, 2014 |
38Monitor | CVE-2014-0769No exploit | Festo CECX-X-(C1/M1) Controller Improper Authenticationfesto · cecx-x-m1 modular controller · CWE-287 | Critical9.3 | — | 2.3% | Apr 25, 2014 |
31Monitor | CVE-2012-4706No exploit | Integer signedness error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to cause a denial of service via a crafted pac3s-software · codesys gateway-server · CWE-189 | High7.8 | — | 1.6% | Feb 24, 2013 |
21Monitor | CVE-2014-0757No exploit | Smart Software Solutions (3S) CoDeSys Runtime Toolkit NULL Pointer Dereference3s-software · codesys runtime toolkit · CWE-476 | Medium5.0 | — | 3.2% | Jan 31, 2014 |
21Monitor | CVE-2015-6482No exploit | Runtime Toolkit before 2.4.7.48 in 3S-Smart CODESYS before 2.3.9.48 allows remote attackers to cause a denial of service (NULL pointer deref3s-software · codesys runtime system | Medium5.0 | — | 2.1% | Oct 18, 2015 |
- CVE-2012-470559Plan
Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors
CriticalCVSS 10.0WeaponizedEPSS 65%3s-software · codesys gateway-serverFeb 24, 2013
- CVE-2012-470842Plan
Stack-based buffer overflow in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted pac
CriticalCVSS 10.0No exploitEPSS 7%3s-software · codesys gateway-serverFeb 24, 2013
- CVE-2012-606841Plan
3S CoDeSys Improper Access Control
CriticalCVSS 9.8No exploitEPSS 5%3s-software · codesys runtime systemJan 21, 2013
- CVE-2012-470441Plan
Array index error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet.
CriticalCVSS 10.0No exploitEPSS 4%3s-software · codesys gateway-serverFeb 24, 2013
- CVE-2013-278141Plan
Use-after-free vulnerability in the server application in 3S CODESYS Gateway 2.3.9.27 allows remote attackers to cause a denial of service (
CriticalCVSS 10.0No exploitEPSS 4%3s-software · codesys gateway-serverMay 23, 2013
- CVE-2012-470741Plan
3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors that trigger an out-of-bounds memory
CriticalCVSS 10.0No exploitEPSS 4%3s-software · codesys gateway-serverFeb 24, 2013
- CVE-2012-606941Plan
3S CoDeSys Relative Path Traversal
CriticalCVSS 10.0No exploitEPSS 3%3s-software · codesys runtime systemJan 21, 2013
- CVE-2018-544040Plan
A Stack-based Buffer Overflow issue was discovered in 3S-Smart CODESYS Web Server.
CriticalCVSS 9.8No exploitEPSS 3%3s-software · codesys runtime systemFeb 15, 2018
- CVE-2014-076038Monitor
Festo CECX-X-(C1/M1) Controller Improper Authentication
CriticalCVSS 9.3No exploitEPSS 3%festo · cecx-x-c1 modular master controllerApr 25, 2014
- CVE-2014-076938Monitor
Festo CECX-X-(C1/M1) Controller Improper Authentication
CriticalCVSS 9.3No exploitEPSS 2%festo · cecx-x-m1 modular controllerApr 25, 2014
- CVE-2012-470631Monitor
Integer signedness error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to cause a denial of service via a crafted pac
HighCVSS 7.8No exploitEPSS 2%3s-software · codesys gateway-serverFeb 24, 2013
- CVE-2014-075721Monitor
Smart Software Solutions (3S) CoDeSys Runtime Toolkit NULL Pointer Dereference
MediumCVSS 5.0No exploitEPSS 3%3s-software · codesys runtime toolkitJan 31, 2014
- CVE-2015-648221Monitor
Runtime Toolkit before 2.4.7.48 in 3S-Smart CODESYS before 2.3.9.48 allows remote attackers to cause a denial of service (NULL pointer deref
MediumCVSS 5.0No exploitEPSS 2%3s-software · codesys runtime systemOct 18, 2015