← Vulnerability feed

Vulnerability record · CVE-2019-9013 · published 15 August 2019

CVE-2019-9013: Codesys control for beaglebone sl broken cryptographic algorithm vulnerability

Codesys · Control For Beaglebone Sl

An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the following CODESYS V3 products in all versions containing the CmpUserMgr component are affected regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS V3 Simulation Runtime (part of the CODESYS Development System), CODESYS Control V3 Runtime System Toolkit, CODESYS HMI V3.

8.8 CVSS 3.1 High EPSS 0.28% · top 81.4% CWE-327 · Broken cryptographic algorithm
8.8CVSS 3.1 base score, v2 5.8
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
12Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the following CODESYS V3 products in all versions containing the CmpUserMgr component are affected regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS V3 Simulation Runtime (part of the CODESYS Development System), CODESYS Control V3 Runtime System Toolkit, CODESYS HMI V3.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-9013 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-9010Codesys control for beaglebone sl vulnerabilityAn issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of a communication channel. All …EPSS 1.9%9.8CVE-2018-10612Codesys control for beaglebone sl improper access control vulnerabilityIn 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not…EPSS 1.3%8.8CVE-2023-6357Codesys control for beaglebone sl os command injection vulnerabilityA low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the…EPSS 0.96%8.8CVE-2022-4046Codesys control for beaglebone sl memory buffer overflow vulnerabilityIn CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user …EPSS 0.88%8.8CVE-2022-47387Codesys control for beaglebone sl out-of-bounds write vulnerabilityAn authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in…EPSS 1.3%8.8CVE-2022-47388Codesys control for beaglebone sl out-of-bounds write vulnerabilityAn authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products i…EPSS 1.3%8.8CVE-2022-47389Codesys control for beaglebone sl out-of-bounds write vulnerabilityAn authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products i…EPSS 1.3%8.8CVE-2022-47390Codesys control for beaglebone sl out-of-bounds write vulnerabilityAn authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products i…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2019-9013), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.