First published: Thu Aug 03 2023(Updated: )
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
CODESYS Control Beaglebone SL | <4.10.0.0 | |
CODESYS Control for empc-a/imx6 | <4.10.0.0 | |
CODESYS Control for IoT2000 | <4.10.0.0 | |
CODESYS Control for Linux | <4.10.0.0 | |
CODESYS Control PFC100 SL | <4.10.0.0 | |
WAGO PFC200 | <4.10.0.0 | |
CODESYS Control for PLCnext | <4.10.0.0 | |
CODESYS Control Raspberry Pi SL | <4.10.0.0 | |
CODESYS Control for WAGO Touch Panels 600 | <4.10.0.0 | |
CODESYS Control RTE | <3.5.19.20 | |
CODESYS Control RTE SL (for Beckhoff CX) | <3.5.19.20 | |
CODESYS Runtime System Toolkit | <3.5.19.20 | |
CODESYS Control Win SL | <3.5.19.20 | |
CODESYS Development System | <3.5.19.20 | |
CODESYS HMI (SL) | <3.5.19.20 | |
CODESYS Safety SIL2 Runtime Toolkit | <3.5.19.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37557 is a vulnerability in multiple versions of Codesys products that can lead to a denial-of-service condition.
Multiple Codesys products in multiple versions, including Codesys Control for Beaglebone Sl, Codesys Control for Empc-a\/imx6 Sl, Codesys Control for Iot2000 Sl, and others, are affected by CVE-2023-37557.
CVE-2023-37557 has a severity rating of 6.5, which is considered medium.
To fix CVE-2023-37557, it is recommended to update to a version of the affected Codesys products that is higher than 4.10.0.0.
You can find more information about CVE-2023-37557 on the VDE CERT website: https://cert.vde.com/en/advisories/VDE-2023-019/