Hundreds of ICS products affected by a critical flaw in CODESYS WebVisu

  • 2 February 2018
  • 0 replies
  • 198 views

Userlevel 7
Badge +54
February 2, 2018  By Pierluigi Paganini
 


 

Researcher discovered a critical vulnerability in the web server component of 3S-Smart Software Solutions’ CODESYS WebVisu product currently used in 116 PLCs and HMIs from many vendors,

 
Security researcher Zhu WenZhe from Istury IOT discovered a critical stack-based buffer overflow vulnerability in the web server component of 3S-Smart Software Solutions’ CODESYS WebVisu product that allows users to view human-machine interfaces (HMIs) for programmable logic controllers (PLCs) in a web browser.
 
The vulnerability is tracked as CVE-2018-5440 and it has been assigned a CVSS score of 9.8, and the worst news is that it is quite easy to exploit.
 
Full Article.

0 replies

Be the first to reply!

Reply