CVE-2023-37558: CODESYS Improper Validation of Consistency within Input in multiple products
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37559
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-37558?
CVE-2023-37558 is a vulnerability that allows an attacker to cause a denial-of-service condition in multiple Codesys products.
How does CVE-2023-37558 affect Codesys products?
CVE-2023-37558 affects multiple versions of Codesys products, potentially leading to a denial-of-service condition.
What is the severity of CVE-2023-37558?
CVE-2023-37558 has a severity rating of 6.5 (medium).
Which Codesys products are affected by CVE-2023-37558?
CVE-2023-37558 affects multiple Codesys products, including Codesys Control For Beaglebone Sl, Codesys Control For Empc-a\/imx6 Sl, Codesys Control For Iot2000 Sl, and more.
Is there a fix for CVE-2023-37558?
To mitigate CVE-2023-37558, it is recommended to update to a version beyond 4.10.0.0 for affected Codesys products.