CVE-2023-3663: CODESYS: Missing integrity check in CODESYS Development System
In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to manipulate the content of notifications received via HTTP by the CODESYS notification server.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this CODESYS Development System vulnerability?
The vulnerability ID for this CODESYS Development System vulnerability is CVE-2023-3663.
What is the severity level of CVE-2023-3663?
The severity level of CVE-2023-3663 is high, with a severity value of 8.8.
What is the impact of the missing integrity check vulnerability in CODESYS Development System?
The missing integrity check vulnerability in CODESYS Development System allows an unauthenticated remote attacker to manipulate the content of notifications received via HTTP by the CODESYS notification server.
Which versions of CODESYS Development System are affected by CVE-2023-3663?
CODESYS Development System versions from 3.5.11.20 to 3.5.19.20 are affected by CVE-2023-3663.
Is there a fix available for CVE-2023-3663?
Yes, users of CODESYS Development System should upgrade to version 3.5.19.20 or later to fix the CVE-2023-3663 vulnerability.