CVE-2011-5007: 3ssoftware Codesys

High severity, CVSS 10.0. EPSS: 72.7% chance of exploitation in the next 30 days.

Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, allows remote attackers to execute arbitrary code via a long URI to TCP port 8080.

Affected products

Published 2011-12-25. Last modified 2026-06-16.