Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/106251 | vdb entry third party advisory |
https://ics-cert.kaspersky.com/advisories/klcert-advisories/2018/12/19/klcert-18-037-codesys-control-v3-use-of-insufficiently-random-values/ | third party advisory mitigation |
https://ics-cert.us-cert.gov/advisories/ICSA-18-352-04 |