3S-Smart Software Solutions GmbH CODESYS Control V3 Online User Management
CODESYS Control and HMI products with versions below 3.5.13.0 contain an improper permissions configuration in the CmpUserMgr component (CWE-732). This allows an authenticated user to bypass role-based access controls and access functionality and information restricted to higher-privilege users. The vulnerability affects CODESYS runtime on multiple platforms including Beckhoff CX, WAGO PFC controllers, Raspberry Pi, BeagleBone, emPC-A/iMX6, IOT2000, and Windows systems, as well as CODESYS HMI V3 and the CODESYS Development System simulation runtime.
- Valid CODESYS user credentials
- Network access to the CODESYS Control or HMI service port
- Service running with CmpUserMgr component enabled
- User management feature in use (not in full-access mode)
Patching may require device reboot — plan for process interruption
/api/v1/advisories/c2b73bc6-2a6b-418c-a147-84293b8d4beeGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.