First published: Thu Aug 03 2023(Updated: )
In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to manipulate the content of notifications received via HTTP by the CODESYS notification server.
Credit: info@cert.vde.com info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
CODESYS Development System | >=3.5.11.20<3.5.19.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this CODESYS Development System vulnerability is CVE-2023-3663.
The severity level of CVE-2023-3663 is high, with a severity value of 8.8.
The missing integrity check vulnerability in CODESYS Development System allows an unauthenticated remote attacker to manipulate the content of notifications received via HTTP by the CODESYS notification server.
CODESYS Development System versions from 3.5.11.20 to 3.5.19.20 are affected by CVE-2023-3663.
Yes, users of CODESYS Development System should upgrade to version 3.5.19.20 or later to fix the CVE-2023-3663 vulnerability.