6.5
CVE-2023-37551
- EPSS 0.06%
- Veröffentlicht 03.08.2023 12:15:10
- Zuletzt bearbeitet 21.11.2024 08:11:55
- Quelle info@cert.vde.com
- CVE-Watchlists
- Unerledigt
In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communication requests can utilize the CmpApp component to download files with any file extensions to the controller. In contrast to the regular file download via CmpFileTransfer, no filtering of certain file types is performed here. As a result, the integrity of the CODESYS control runtime system may be compromised by the files loaded onto the controller.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Codesys ≫ Control For Beaglebone Sl Version < 4.10.0.0
Codesys ≫ Control For Empc-a/imx6 Sl Version < 4.10.0.0
Codesys ≫ Control For Iot2000 Sl Version < 4.10.0.0
Codesys ≫ Control For Linux Sl Version < 4.10.0.0
Codesys ≫ Control For Pfc100 Sl Version < 4.10.0.0
Codesys ≫ Control For Pfc200 Sl Version < 4.10.0.0
Codesys ≫ Control For Plcnext Sl Version < 4.10.0.0
Codesys ≫ Control For Raspberry Pi Sl Version < 4.10.0.0
Codesys ≫ Control For Wago Touch Panels 600 Sl Version < 4.10.0.0
Codesys ≫ Control Rte Sl Version < 3.5.19.20
Codesys ≫ Control Rte Sl (for Beckhoff Cx) Version < 3.5.19.20
Codesys ≫ Control Runtime System Toolkit Version < 3.5.19.20
Codesys ≫ Control Win Sl Version < 3.5.19.20
Codesys ≫ Development System Version < 3.5.19.20
Codesys ≫ Safety Sil2 Version < 3.5.19.20
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.193 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
| info@cert.vde.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-552 Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.