High severity7.5NVD Advisory· Published Feb 19, 2019· Updated Jun 17, 2026
CVE-2018-20025
CVE-2018-20025
Description
Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17- cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:*Range: >=3.0,<3.5.14.0
- cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:*Range: >=3.0,<3.5.14.0
cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*range: >=3.0,<3.5.14.0
- cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:*range: >=3.0,<3.5.14.0
- cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:*Range: >=3.0,<3.5.14.0
- cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:*Range: >=3.0,<3.5.14.0
- cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*Range: >=3.0,<3.5.14.0
- cpe:2.3:a:codesys:control_rte_sl_\(for_beckhoff_cx\):*:*:*:*:*:*:*:*Range: >=3.0,<3.5.14.0
- cpe:2.3:a:codesys:control_runtime_toolkit:*:*:*:*:*:*:*:*Range: >=3.0,<3.5.14.0
- cpe:2.3:a:codesys:development_system:*:*:*:*:*:*:*:*Range: >=3.0,<3.5.14.0
- Kaspersky Lab/CODESYS V3 productsv5Range: prior V3.5.14.0
Patches
Vulnerability mechanics
References
3- www.securityfocus.com/bid/106251nvdThird Party AdvisoryVDB Entry
- ics-cert.kaspersky.com/advisories/klcert-advisories/2018/12/19/klcert-18-037-codesys-control-v3-use-of-insufficiently-random-values/nvdMitigationThird Party Advisory
- ics-cert.us-cert.gov/advisories/ICSA-18-352-04nvd
News mentions
0No linked articles in our index yet.