High severity7.5NVD Advisory· Published Sep 13, 2019· Updated Jun 17, 2026
CVE-2019-13532
CVE-2019-13532
Description
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15- cpe:2.3:a:codesys:control_for_beaglebone:*:*:*:*:*:*:*:*Range: <3.5.14.10
- cpe:2.3:a:codesys:control_for_empc-a\/imx6:*:*:*:*:*:*:*:*Range: <3.5.14.10
- cpe:2.3:a:codesys:control_for_raspberry_pi:*:*:*:*:*:*:*:*Range: <3.5.14.10
- cpe:2.3:a:codesys:control_runtime_system_toolkit:*:*:*:*:*:*:*:*Range: >=3.0,<3.5.12.80
- cpe:2.3:a:codesys:embedded_target_visu_toolkit:*:*:*:*:*:*:*:*Range: >=3.0,<3.5.12.80
- cpe:2.3:a:codesys:remote_target_visu_toolkit:*:*:*:*:*:*:*:*Range: >=3.0,<3.5.12.80
- CODESYS/V3 web serverdescription
- Range: <3.5.14.10
Patches
Vulnerability mechanics
References
1- www.us-cert.gov/ics/advisories/icsa-19-255-01nvdMitigationPatchThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.