CVE-2023-3662: CODESYS: Vulnerability in CODESYS Development System allows for execution of binaries
Published Aug 3, 2023
·Updated
In CODESYS Development System versions from 3.5.17.0 and prior to 3.5.19.20 a vulnerability allows for execution of binaries from the current working directory in the users context .
Affected Software
1 affected component
CODESYS Development System>=3.5.17.0<3.5.19.20
Event History
Aug 3, 2023
CVE Published
via MITRE·10:55 AM
Data Sourced
via MITRE·10:55 AM
DescriptionSeverityWeakness
Data Sourced
11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-3662.
2
What is the title of the vulnerability?
The title of the vulnerability is 'In CODESYS Development System versions from 3.5.17.0 and prior to 3.5.19.20 a vulnerability allows for execution of binaries from the current working directory in the users context.'
3
What is the affected software?
The affected software is CODESYS Development System version 3.5.17.0 and prior to 3.5.19.20.
4
What is the severity of CVE-2023-3662?
The severity of CVE-2023-3662 is high with a severity value of 7.3.
5
How can I fix CVE-2023-3662?
To fix CVE-2023-3662, update the CODESYS Development System to version 3.5.19.20 or later.