CVE-2023-3669: CODESYS: Missing Brute-Force protection in CODESYS Development System
Published Aug 3, 2023
·Updated
A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimited attempts of guessing the password within an import dialog.
Affected Software
1 affected component
CODESYS Development System<3.5.19.20
Event History
Aug 3, 2023
CVE Published
via MITRE·11:11 AM
Data Sourced
via MITRE·11:11 AM
DescriptionSeverityWeakness
Data Sourced
12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-3669.
2
What is the severity of CVE-2023-3669?
The severity of CVE-2023-3669 is low, with a severity value of 3.3.
3
What software is affected by CVE-2023-3669?
The CODESYS Development System prior to version 3.5.19.20 is affected by CVE-2023-3669.
4
What is the impact of CVE-2023-3669?
The impact of CVE-2023-3669 is that a local attacker can have unlimited attempts to guess the password within an import dialog.
5
How can I mitigate CVE-2023-3669?
To mitigate CVE-2023-3669, it is recommended to update to version 3.5.19.20 of the CODESYS Development System or later.