← Vulnerability feed

Vulnerability record · CVE-2012-4705 · published 24 February 2013

CVE-2012-4705: CODESYS Gateway-Server path traversal enables remote code execution

33s Software · Codesys Gateway Server

3S CODESYS Gateway-Server before 2.3.9.27 contains a directory traversal flaw (CWE-22) reachable through a crafted pathname. Because the traversal can lead to arbitrary code execution, an unauthenticated network attacker can fully compromise the affected service. The record does not list specific affected builds beyond the fixed version 2.3.9.27.

10.0 CVSS 2.0 High EPSS 65% · top 0.8% CWE-22 · Path traversal
10.0CVSS 2.0 base score
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors involving a crafted pathname.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityUnauthenticated network-reachable path traversal leading to arbitrary code execution with a CVSS 2.0 score of 10 and very high EPSS, though no KEV listing or confirmed in-the-wild exploitation is recorded.

What it is

3S CODESYS Gateway-Server before 2.3.9.27 contains a directory traversal flaw (CWE-22) reachable through a crafted pathname. Because the traversal can lead to arbitrary code execution, an unauthenticated network attacker can fully compromise the affected service. The record does not list specific affected builds beyond the fixed version 2.3.9.27.

Impact

An attacker gains remote code execution with full confidentiality, integrity and availability impact on the Gateway-Server host. This can allow control of the industrial engineering gateway and any systems it brokers access to.

Attack surface

Reachable over the network via the Gateway-Server service, per the AV:N vector; no authentication (Au:N) and no user interaction are required. The description does not specify the exact port or protocol, only that a crafted pathname is involved.

Exploitation

Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is 0.6487 (99.21st percentile), indicating a high modeled likelihood of exploitation activity. No public exploit or in-the-wild confirmation is stated in the record.

What to do

  • Upgrade CODESYS Gateway-Server to 2.3.9.27 or later, which the advisory identifies as the fixed version.
  • If immediate patching is not possible, restrict network access to the Gateway-Server to trusted engineering hosts and block it from untrusted networks.
  • Place the Gateway-Server behind a firewall or segmented industrial zone so it is not directly reachable from general IT or internet-facing networks.
  • Monitor ICS-CERT advisory ICSA-13-050-01A for vendor guidance and any updated fixed versions.
  • Audit the Gateway-Server host for unexpected processes or files after any suspected traversal attempt.

Detection

  • Inspect Gateway-Server logs for pathnames containing traversal sequences such as ../ or encoded variants.
  • Alert on unexpected child processes or file writes spawned by the Gateway-Server service.
  • Monitor network traffic to the Gateway-Server for anomalous requests from hosts outside the engineering subnet.
  • Baseline normal Gateway-Server client connections and flag new or unusual source addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-4705 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-27813s-software codesys gateway-server vulnerabilityUse-after-free vulnerability in the server application in 3S CODESYS Gateway 2.3.9.27 allows remote attackers to cause a denial of service (daemon cr…EPSS 3.8%10.0CVE-2012-47043s-software codesys gateway-server improper input validation vulnerabilityArray index error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet.EPSS 4.2%10.0CVE-2012-47073s-software codesys gateway-server code injection vulnerability3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors that trigger an out-of-bounds memory access.EPSS 3.6%10.0CVE-2012-47083s-software codesys gateway-server memory buffer overflow vulnerabilityStack-based buffer overflow in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet.EPSS 7.4%7.8CVE-2012-47063s-software codesys gateway-server vulnerabilityInteger signedness error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to cause a denial of service via a crafted packet that …EPSS 1.6%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed

Source: NIST National Vulnerability Database (record CVE-2012-4705), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.