Vulnerability record · CVE-2012-4705 · published 24 February 2013
CVE-2012-4705: CODESYS Gateway-Server path traversal enables remote code execution
33s Software · Codesys Gateway Server
3S CODESYS Gateway-Server before 2.3.9.27 contains a directory traversal flaw (CWE-22) reachable through a crafted pathname. Because the traversal can lead to arbitrary code execution, an unauthenticated network attacker can fully compromise the affected service. The record does not list specific affected builds beyond the fixed version 2.3.9.27.
Description
Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors involving a crafted pathname.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated network-reachable path traversal leading to arbitrary code execution with a CVSS 2.0 score of 10 and very high EPSS, though no KEV listing or confirmed in-the-wild exploitation is recorded.
What it is
3S CODESYS Gateway-Server before 2.3.9.27 contains a directory traversal flaw (CWE-22) reachable through a crafted pathname. Because the traversal can lead to arbitrary code execution, an unauthenticated network attacker can fully compromise the affected service. The record does not list specific affected builds beyond the fixed version 2.3.9.27.
Impact
An attacker gains remote code execution with full confidentiality, integrity and availability impact on the Gateway-Server host. This can allow control of the industrial engineering gateway and any systems it brokers access to.
Attack surface
Reachable over the network via the Gateway-Server service, per the AV:N vector; no authentication (Au:N) and no user interaction are required. The description does not specify the exact port or protocol, only that a crafted pathname is involved.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is 0.6487 (99.21st percentile), indicating a high modeled likelihood of exploitation activity. No public exploit or in-the-wild confirmation is stated in the record.
What to do
- Upgrade CODESYS Gateway-Server to 2.3.9.27 or later, which the advisory identifies as the fixed version.
- If immediate patching is not possible, restrict network access to the Gateway-Server to trusted engineering hosts and block it from untrusted networks.
- Place the Gateway-Server behind a firewall or segmented industrial zone so it is not directly reachable from general IT or internet-facing networks.
- Monitor ICS-CERT advisory ICSA-13-050-01A for vendor guidance and any updated fixed versions.
- Audit the Gateway-Server host for unexpected processes or files after any suspected traversal attempt.
Detection
- Inspect Gateway-Server logs for pathnames containing traversal sequences such as ../ or encoded variants.
- Alert on unexpected child processes or file writes spawned by the Gateway-Server service.
- Monitor network traffic to the Gateway-Server for anomalous requests from hosts outside the engineering subnet.
- Baseline normal Gateway-Server client connections and flag new or unusual source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-4705 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-4705), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.