A heap overflow vulnerability exists in CmpWebServerHandlerV3.dll (file version 3.5.15.20) due to improper validation of user-supplied data sent to the CODESYS V3 web server URL endpoint /WebVisuV3.The vulnerability (CVE-2020-10245) could hence allow an unauthenticated attacker to crash a target system or execute arbitrary codes on it. It was even possible for an adversary to exploit the bug remotely.
The researchers have also shared PoC exploit code for the vulnerability.
As stated in their advisory, the flaw affects all CODESYS V3 runtime systems with earlier web server versions. They labeled the vulnerability as a critical and easily exploitable flaw. Explaining the severity of the flaw, their advisory reads,
Specific crafted requests may cause a heap-based buffer overflow. Further on this could crash the web server, lead to a denial-of-service condition or may be utilized for remote code execution. As the webserver is part of the CODESYS runtime system, this may result in unforeseen behavior of the complete runtime system.For now, they have confirmed no specific exploitation of the bug in the wild.