Vulnerabilities > CVE-2011-5009 - Unspecified vulnerability in 3Ssoftware Codesys 3.4

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
3ssoftware
exploit available

Summary

The CmpWebServer.dll module in the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a crafted Content-Length in an HTTP POST or (2) an invalid HTTP request method.

Vulnerable Configurations

Part Description Count
Application
3Ssoftware
1

Exploit-Db

  • descriptionNULL Pointer Invalid HTTP Request Parsing Remote DoS. CVE-2011-5009. Dos exploits for multiple platform
    idEDB-ID:36378
    last seen2016-02-04
    modified2011-11-30
    published2011-11-30
    reporterLuigi Auriemma
    sourcehttps://www.exploit-db.com/download/36378/
    titleCoDeSys 3.4 NULL Pointer Invalid HTTP Request Parsing Remote DoS
  • descriptionCoDeSys 3.4 HTTP POST Request NULL Pointer Content-Length Parsing Remote DoS. CVE-2011-5009. Dos exploits for multiple platform
    idEDB-ID:36377
    last seen2016-02-04
    modified2011-11-30
    published2011-11-30
    reporterLuigi Auriemma
    sourcehttps://www.exploit-db.com/download/36377/
    titleCoDeSys 3.4 HTTP POST Request NULL Pointer Content-Length Parsing Remote DoS