CVE-2023-37557: CODESYS Heap-based Buffer Overflow in multiple products
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-37557?
CVE-2023-37557 is a vulnerability in multiple versions of Codesys products that can lead to a denial-of-service condition.
Which products are affected by CVE-2023-37557?
Multiple Codesys products in multiple versions, including Codesys Control for Beaglebone Sl, Codesys Control for Empc-a\/imx6 Sl, Codesys Control for Iot2000 Sl, and others, are affected by CVE-2023-37557.
What is the severity of CVE-2023-37557?
CVE-2023-37557 has a severity rating of 6.5, which is considered medium.
How can CVE-2023-37557 be fixed?
To fix CVE-2023-37557, it is recommended to update to a version of the affected Codesys products that is higher than 4.10.0.0.
Where can I find more information about CVE-2023-37557?
You can find more information about CVE-2023-37557 on the VDE CERT website: https://cert.vde.com/en/advisories/VDE-2023-019/