Critical severity9.8NVD Advisory· Published Jan 29, 2019· Updated Jun 17, 2026
CVE-2018-10612
CVE-2018-10612
Description
In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15- cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:*Range: >=3.0,<3.5.14.0
- cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:*Range: >=3.0,<3.5.14.0
cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*range: >=3.0,<3.5.14.0
- cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:*range: >=3.0,<3.5.14.0
- cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:*Range: >=3.0,<3.5.14.0
- cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:*Range: >=3.0,<3.5.14.0
- cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*Range: >=3.0,<3.5.14.0
- cpe:2.3:a:codesys:control_runtime_toolkit:*:*:*:*:*:*:*:*Range: >=3.0,<3.5.14.0
- cpe:2.3:a:codesys:development_system_v3:*:*:*:*:*:*:*:*Range: >=3.0,<3.5.14.0
- Range: <3.5.14.0
- Range: <3.5.14.0
- 3S Smart Software Solutions/3s Smart Software Solutions Gmbh Codesys Control V3 Products Prior To Version 3.5.14.0v5Range: 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0
Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/106248nvdThird Party AdvisoryVDB Entry
- ics-cert.us-cert.gov/advisories/ICSA-18-352-03nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.