8.8
CVE-2023-3663
- EPSS 0.49%
- Veröffentlicht 03.08.2023 11:15:10
- Zuletzt bearbeitet 21.11.2024 08:17:47
- Quelle info@cert.vde.com
- CVE-Watchlists
- Unerledigt
In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to manipulate the content of notifications received via HTTP by the CODESYS notification server.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Codesys ≫ Development System Version >= 3.5.11.20 < 3.5.19.20
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.49% | 0.647 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| info@cert.vde.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-940 Improper Verification of Source of a Communication Channel
The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.