Search by:
19 December 2018
KLCERT-18-037: CodeSYS Control V3 Use of Insufficiently Random Values
Vendor
CodeSYS
CVE-IDS
KLCERT
KLCERT-18-037
Timeline
Timeline
Kaspersky ICS CERT advisory published
19 December 2018
Vendor releases patch
December 2018
Vulnerabilities reported
July 2018
CVSS v3
Exploitability
Remotely
Existence of exploit
Unknown
Affected products
All variants of the following CODESYS V3 products in all versions prior V3.5.14.0 containing communication servers for the CODESYS communication protocol are affected, regardless of the CPU type or the operating system:
Mitigation
Vendor mitigation
3S-Smart Software Solutions GmbH has released version V3.5.14.0 to solve the noted vulnerability issue for all affected CODESYS products.
Currently, 3S-Smart Software Solutions GmbH has not identified any workarounds for this vulnerability.
In general, 3S-Smart Software Solutions GmbH recommends the following defensive measures as part of the mitigation strategy to reduce the risk of exploitation of this vulnerability:
Kaspersky Lab publishes information on newly identified vulnerabilities in order to raise user awareness of the IT security threats detected. Kaspersky Lab does not make any guarantees in respect of information received from vendors of products in which vulnerabilities have been identified, which is included in the following sections of the advisory: Affected Products, Vendor Mitigation.
Timeline
Kaspersky ICS CERT advisory published
19 December 2018
Vendor releases patch
December 2018
Vulnerabilities reported
July 2018