Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-39347 | A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication vulnerability which could lead to full system access and/or DoS. |
| Link | Providers |
|---|---|
| https://cert.vde.com/en/advisories/VDE-2024-047 |
|
Tue, 10 Dec 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 18 Nov 2024 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication vulnerability which could lead to full system access and/or DoS. | |
| Title | WAGO: CODESYS V3 Configuration Authentication Bypass in Multiple Devices | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-01-30T09:21:40.910Z
Reserved: 2024-07-25T09:07:31.464Z
Link: CVE-2024-41969
Updated: 2024-12-10T16:59:32.790Z
Status : Deferred
Published: 2024-11-18T09:15:05.637
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-41969
No data.
OpenCVE Enrichment
No data.
EUVD