microsoft / CoDe16

Microsoft’s cyber physical system researchers recently identified multiple high-severity vulnerabilities in the CODESYS V3 software development kit (SDK)
MIT License
45 stars 7 forks source link

Exposure to vulnerability #1

Open SLAMsec opened 1 year ago

SLAMsec commented 1 year ago

Hello,

We are trying to determine our exposure to this issue. If a device is running CODESYS 64 3.5 would it be vulnerable to this? If the software is simply installed on a Windows PC is it vulnerable? Are you able to provide a filename of what we should be looking for on Windows PCs to see if it is vulnerable? Any assistance you can offer would be great.

Thanks,

SLAM

SLAMsec commented 1 year ago

Also would PLCHandler be vulnerable?

regevx-cyberx commented 5 months ago

@SLAMsec Sorry for the late response, if it still relevant, every CodeSys version 3.5 and above is vulnerable to those vulnerabilities, even if installed on Windows machine. In order to check if your Windows Machine is vulnerable or not, check your Codesys version which installed on the PC, if it prior to version 3.5.19.0 your machine is vulnerable, you should update your Codesys software to 3.5.19.0