CVE-2023-37550: CODESYS: Improper Input Validation in CmpApp component
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546, CVE-2023-37547, CVE-2023-37548 and CVE-2023-37549.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-37550?
CVE-2023-37550 is a vulnerability in multiple Codesys products that can cause a denial-of-service condition.
How severe is CVE-2023-37550?
CVE-2023-37550 has a severity rating of 6.5 (medium severity).
Which Codesys products are affected by CVE-2023-37550?
The vulnerability CVE-2023-37550 affects multiple versions of the following Codesys products: Codesys Control For Beaglebone Sl, Codesys Control For Empc-a/imx6 Sl, Codesys Control For Iot2000 Sl, Codesys Control For Linux Sl, Codesys Control For Pfc100 Sl, Codesys Control For Pfc200 Sl, Codesys Control For Plcnext Sl, Codesys Control For Raspberry Pi Sl, Codesys Control For Wago Touch Panels 600 Sl, Codesys Control Rte Sl, Codesys Control Rte Sl (for Beckhoff Cx), Codesys Control Runtime System Toolkit, Codesys Control Win Sl, CODESYS Development System, Codesys Hmi, and Codesys Safety Sil2.
How can CVE-2023-37550 be fixed?
To fix CVE-2023-37550, it is recommended to update the affected Codesys products to a version that is not vulnerable.
Where can I find more information about CVE-2023-37550?
You can find more information about CVE-2023-37550 at the following reference link: [https://cert.vde.com/en/advisories/VDE-2023-019](https://cert.vde.com/en/advisories/VDE-2023-019)