← Vulnerability feed

Vulnerability record · CVE-2011-5007 · published 25 December 2011

CVE-2011-5007: 3S CoDeSys CmpWebServer stack buffer overflow via long URI

33ssoftware · Codesys

The CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, contains a stack-based buffer overflow (CWE-119). A remote attacker can trigger it by sending a long URI to TCP port 8080, which can lead to arbitrary code execution on the affected device.

10.0 CVSS 2.0 High EPSS 73% · top 0.6% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, allows remote attackers to execute arbitrary code via a long URI to TCP port 8080.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 2.0 score of 10 with network-reachable, unauthenticated remote code execution, a public exploit and very high EPSS make this a top-priority patch for exposed CoDeSys and ABB AC500 systems.

What it is

The CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, contains a stack-based buffer overflow (CWE-119). A remote attacker can trigger it by sending a long URI to TCP port 8080, which can lead to arbitrary code execution on the affected device.

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code in the context of the CmpWebServer process, giving full control over confidentiality, integrity and availability of the device.

Attack surface

Reachable over the network via TCP port 8080 with no authentication required, per the CVSS vector AV:N/AC:L/Au:N and the description of a long URI to the web server. No user interaction is indicated.

Exploitation

A public exploit exists (Exploit-DB entry tagged Exploit) and EPSS is very high at 0.72714 (99.4th percentile), though the CVE is not listed in CISA KEV. No ransomware usage is documented.

What to do

  • Upgrade CoDeSys to a version later than 3.4 SP4 Patch 2, or apply the vendor fix referenced in the ICS-CERT advisory ICSA-12-320-01.
  • Restrict network access to TCP port 8080 on affected PLCs and CoDeSys hosts using firewalls or network segmentation.
  • Place affected devices behind an industrial DMZ and avoid exposing the web server to untrusted networks.
  • Monitor vendor and ICS-CERT advisories for updated guidance on ABB AC500 and other affected products.

Detection

  • Inspect web server or IDS/IPS logs for unusually long or malformed URIs sent to TCP port 8080 on CoDeSys/ABB AC500 devices.
  • Alert on crashes or restarts of the CmpWebServer process, which may indicate a failed overflow attempt.
  • Baseline normal URI lengths and patterns for the CoDeSys web interface and alert on deviations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-5007 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2011-50083ssoftware codesys vulnerabilityInteger overflow in the GatewayService component in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to execute arbitrary code via a large size val…EPSS 5.0%6.4CVE-2011-50583ssoftware codesys permissions and access controls vulnerabilityThe CmbWebserver.dll module of the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to create arbitrary directories under the we…EPSS 1.8%5.0CVE-2011-50093ssoftware codesys vulnerabilityThe CmpWebServer.dll module in the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to cause a denial of service (NULL pointer d…EPSS 10%8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed8.8CVE-2026-3910Google Chrome V8 improper implementation allows sandbox code executionChrome before 146.0.7680.75 contains an inappropriate implementation in the V8 JavaScript engine, classified as code injection and memory buffer over…KEVEPSS 1.0%analysed

Source: NIST National Vulnerability Database (record CVE-2011-5007), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.