First published: Thu Aug 03 2023(Updated: )
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37547, CVE-2023-37548, CVE-2023-37549 and CVE-2023-37550
Credit: info@cert.vde.com info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
CODESYS Control Beaglebone SL | <4.10.0.0 | |
CODESYS Control for empc-a/imx6 | <4.10.0.0 | |
CODESYS Control for IoT2000 | <4.10.0.0 | |
CODESYS Control for Linux SL | <4.10.0.0 | |
CODESYS Control for PFC100 SL | <4.10.0.0 | |
CODESYS Control for pfc200 SL | <4.10.0.0 | |
CODESYS Control for PLCnext SL | <4.10.0.0 | |
CODESYS Raspberry Pi | <4.10.0.0 | |
CODESYS Control for WAGO Touch Panels 600 | <4.10.0.0 | |
CODESYS Control RTE | <3.5.19.20 | |
CODESYS Control RTE SL (for Beckhoff CX) | <3.5.19.20 | |
CODESYS Runtime System Toolkit | <3.5.19.20 | |
CODESYS Control Win SL | <3.5.19.20 | |
CODESYS Development System | <3.5.19.20 | |
CODESYS HMI (SL) | <3.5.19.20 | |
CODESYS Safety SIL2 Runtime Toolkit | <3.5.19.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37546 is a vulnerability found in multiple Codesys products that can cause a denial-of-service condition.
CVE-2023-37546 affects multiple versions of Codesys products, leading to a denial-of-service condition.
CVE-2023-37546 has a severity rating of 6.5, which is considered medium.
To fix CVE-2023-37546, it is recommended to update the affected Codesys products to version 4.10.0.0 or later.
You can find more information about CVE-2023-37546 at the following link: https://cert.vde.com/en/advisories/VDE-2023-019