Vulnerability Name:

CVE-2013-2781 (CCN-84468)

Assigned:2013-05-22
Published:2013-05-22
Updated:2013-05-23
Summary:Use-after-free vulnerability in the server application in 3S CODESYS Gateway 2.3.9.27 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-399
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2013-2781

Source: MISC
Type: US Government Resource
http://ics-cert.us-cert.gov/advisories/ICSA-13-142-01

Source: CCN
Type: SA53515
3S CoDeSys Gateway Server Use-After-Free Vulnerability

Source: CCN
Type: CODESYS Web site
CODESYS Download

Source: CCN
Type: BID-60088
CODESYS Gateway Server Use After Free Remote Denial of Service Vulnerability

Source: XF
Type: UNKNOWN
codesys-cve20132781-code-exec(84468)

Source: CCN
Type: ICSA-13-142-01
CODESYS–Gateway Use After Free

Vulnerable Configuration:Configuration 1:
  • cpe:/a:3s-software:codesys_gateway-server:2.3.9.27:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    3s-software codesys gateway-server 2.3.9.27