CVE-2019-9008: Codesys Control For Beaglebone

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over the runtime.

Affected products

  • Codesys Control For Beaglebone: before 3.5.13.0 (fixed in 3.5.13.0)
  • Codesys Control For Empc-a/imx6: before 3.5.13.0 (fixed in 3.5.13.0)
  • Codesys Control For IOT2000: before 3.5.13.0 (fixed in 3.5.13.0)
  • Codesys Control For PFC100: before 3.5.13.0 (fixed in 3.5.13.0)
  • Codesys Control For PFC200: before 3.5.13.0 (fixed in 3.5.13.0)
  • Codesys Control For Raspberry Pi: before 3.5.13.0 (fixed in 3.5.13.0)
  • Codesys Control Rte: before 3.5.13.0 (fixed in 3.5.13.0)
  • Codesys Control Win: before 3.5.13.0 (fixed in 3.5.13.0)
  • Codesys HMI: before 3.5.13.0 (fixed in 3.5.13.0)
  • Codesys Simulation Runtime: before 3.5.13.0 (fixed in 3.5.13.0)

Published 2019-09-17. Last modified 2026-06-17.