VYPR
Unrated severityNVD Advisory· Published Sep 17, 2019· Updated Aug 4, 2024

CVE-2019-13542

CVE-2019-13542

Description

3S-Smart Software Solutions GmbH CODESYS V3 OPC UA Server, all versions 3.5.11.0 to 3.5.15.0, allows an attacker to send crafted requests from a trusted OPC UA client that cause a NULL pointer dereference, which may trigger a denial-of-service condition.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A NULL pointer dereference in CODESYS V3 OPC UA Server versions 3.5.11.0 to 3.5.15.0 allows denial of service via crafted requests from trusted OPC UA clients.

Vulnerability

The vulnerability is a NULL pointer dereference in the CODESYS V3 OPC UA Server, affecting all versions from 3.5.11.0 to 3.5.15.0. The flaw exists in the OPC UA server component that supports OPC UA Security. An attacker can trigger it by sending specific crafted requests from a trusted OPC UA client. Affected products include CODESYS Control for BeagleBone, emPC-A/iMX6, IOT2000, Linux, PFC100, PFC200, Raspberry Pi, RTE V3, RTE V3 (for Beckhoff CX), Win V3, and the Runtime System Toolkit [1].

Exploitation

The attacker must be a trusted OPC UA client with network access to the server. No additional privileges beyond being a legitimate client are required. The attacker sends specifically crafted OPC UA requests that cause a NULL pointer dereference, leading to a crash. The attack is remotely exploitable with low skill level [1].

Impact

Successful exploitation results in a denial-of-service condition, rendering the OPC UA server unavailable. There is no impact on confidentiality or integrity, as indicated by the CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) [1].

Mitigation

3S-Smart Software Solutions GmbH released version 3.5.15.0 to fix this vulnerability [1]. Users should update to this version or later. General defense measures include using controllers and devices in protected environments to reduce network exposure [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.