CVE-2019-13542

3S-Smart Software Solutions GmbH CODESYS V3 OPC UA Server, all versions 3.5.11.0 to 3.5.15.0, allows an attacker to send crafted requests from a trusted OPC UA client that cause a NULL pointer dereference, which may trigger a denial-of-service condition.
References
Link Resource
https://www.us-cert.gov/ics/advisories/icsa-19-255-04 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:codesys:control_for_beaglebone:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_empc-a\/imx6:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_iot2000:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc100:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc200:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_raspberry_pi:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_win:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:linux:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:runtime_system_toolkit:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-09-17 19:15

Updated : 2023-12-10 12:59


NVD link : CVE-2019-13542

Mitre link : CVE-2019-13542

CVE.ORG link : CVE-2019-13542


JSON object : View

Products Affected

codesys

  • linux
  • control_for_beaglebone
  • runtime_system_toolkit
  • control_for_pfc200
  • control_for_raspberry_pi
  • control_for_empc-a\/imx6
  • control_for_pfc100
  • control_win
  • control_rte
  • control_for_iot2000
CWE
CWE-476

NULL Pointer Dereference