Vulnerability record · CVE-2011-5007 · published 25 December 2011
CVE-2011-5007: 3S CoDeSys CmpWebServer stack buffer overflow via long URI
33ssoftware · Codesys
The CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, contains a stack-based buffer overflow (CWE-119). A remote attacker can trigger it by sending a long URI to TCP port 8080, which can lead to arbitrary code execution on the affected device.
Description
Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, allows remote attackers to execute arbitrary code via a long URI to TCP port 8080.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10 with network-reachable, unauthenticated remote code execution, a public exploit and very high EPSS make this a top-priority patch for exposed CoDeSys and ABB AC500 systems.
What it is
The CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, contains a stack-based buffer overflow (CWE-119). A remote attacker can trigger it by sending a long URI to TCP port 8080, which can lead to arbitrary code execution on the affected device.
Impact
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code in the context of the CmpWebServer process, giving full control over confidentiality, integrity and availability of the device.
Attack surface
Reachable over the network via TCP port 8080 with no authentication required, per the CVSS vector AV:N/AC:L/Au:N and the description of a long URI to the web server. No user interaction is indicated.
Exploitation
A public exploit exists (Exploit-DB entry tagged Exploit) and EPSS is very high at 0.72714 (99.4th percentile), though the CVE is not listed in CISA KEV. No ransomware usage is documented.
What to do
- Upgrade CoDeSys to a version later than 3.4 SP4 Patch 2, or apply the vendor fix referenced in the ICS-CERT advisory ICSA-12-320-01.
- Restrict network access to TCP port 8080 on affected PLCs and CoDeSys hosts using firewalls or network segmentation.
- Place affected devices behind an industrial DMZ and avoid exposing the web server to untrusted networks.
- Monitor vendor and ICS-CERT advisories for updated guidance on ABB AC500 and other affected products.
Detection
- Inspect web server or IDS/IPS logs for unusually long or malformed URIs sent to TCP port 8080 on CoDeSys/ABB AC500 devices.
- Alert on crashes or restarts of the CmpWebServer process, which may indicate a failed overflow attempt.
- Baseline normal URI lengths and patterns for the CoDeSys web interface and alert on deviations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-5007 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-5007), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.