CVE-2019-13548: Codesys Control For Beaglebone
Critical severity, CVSS 9.8. EPSS: 5.8% chance of exploitation in the next 30 days.
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution.
Affected products
- Codesys Control For Beaglebone: before 3.5.14.10 (fixed in 3.5.14.10)
- Codesys Control For Empc-a/imx6: before 3.5.14.10 (fixed in 3.5.14.10)
- Codesys Control For IOT2000: before 3.5.14.10 (fixed in 3.5.14.10)
- Codesys Control For Linux: before 3.5.14.10 (fixed in 3.5.14.10)
- Codesys Control For PFC100: before 3.5.14.10 (fixed in 3.5.14.10)
- Codesys Control For PFC200: before 3.5.14.10 (fixed in 3.5.14.10)
- Codesys Control For Raspberry Pi: before 3.5.14.10 (fixed in 3.5.14.10)
- Codesys Control Rte: from 3.5.8.60, before 3.5.12.80 (fixed in 3.5.12.80); from 3.5.13.0, before 3.5.14.10 (fixed in 3.5.14.10)
- Codesys Control Runtime System Toolkit: from 3.0, before 3.5.12.80 (fixed in 3.5.12.80)
- Codesys Control Win: from 3.5.9.80, up to and including 3.5.12.80; from 3.5.13.0, before 3.5.14.10 (fixed in 3.5.14.10)
- Codesys Embedded Target Visu Toolkit: from 3.0, before 3.5.12.80 (fixed in 3.5.12.80)
- Codesys HMI: from 3.5.10.0, before 3.5.12.80 (fixed in 3.5.12.80); from 3.5.13.0, before 3.5.14.10 (fixed in 3.5.14.10)
- Codesys Remote Target Visu Toolkit: from 3.0, before 3.5.12.80 (fixed in 3.5.12.80)
Published 2019-09-13. Last modified 2026-06-17.