Home
MEDIUM: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
0.0.0.0 (semver) before 4.8.0.0
affected
Description
An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization template files or static elements by means of forced browsing.
Problem types
CWE-425: Direct Request ('Forced Browsing')
Product status
0.0.0.0 (semver) before 4.8.0.0
Credits
M. Ankith by Honeywell
References
certvde.com/en/advisories/VDE-2025-027