5
CVSSv2

CVE-2011-5009

Published: 25/12/2011 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 510
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The CmpWebServer.dll module in the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote malicious users to cause a denial of service (NULL pointer dereference) via (1) a crafted Content-Length in an HTTP POST or (2) an invalid HTTP request method.

Vulnerable Product Search on Vulmon Subscribe to Product

3ssoftware codesys 3.4

Exploits

source: wwwsecurityfocuscom/bid/50854/info CoDeSys is prone to multiple denial-of-service vulnerabilities An attacker can exploit these issues to crash the application and deny service to legitimate users udpsz -T -c "POST / HTTP/10\r\nContent-Length: 4294967295\r\n\r\n" SERVER 8080 -1 ...
source: wwwsecurityfocuscom/bid/50854/info CoDeSys is prone to multiple denial-of-service vulnerabilities An attacker can exploit these issues to crash the application and deny service to legitimate users udpsz -T -c "BLAH / HTTP/10\r\n\r\n" SERVER 8080 -1 ...