9.8

CVE-2023-3935

Wibu: Buffer Overflow in CodeMeter Runtime

A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wibu ≫ Codemeter Runtime Version < 7.60c
Trumpf ≫ Oseon Version >= 1.0.0 <= 3.0.22
Trumpf ≫ Programmingtube Version >= 1.0.1 <= 4.6.3
Trumpf ≫ Teczonebend Version >= 18.02.r8 <= 23.06.01
Trumpf ≫ Tops Unfold Version 05.03.00.00
Trumpf ≫ Topscalculation Version >= 14.00 <= 22.00.00
Trumpf ≫ Trumpflicenseexpert Version >= 1.5.2 <= 1.11.1
Trumpf ≫ Trutops Version >= 08.00 <= 12.01.00.00
Trumpf ≫ Trutops Cell Classic Version <= 09.09.02
Trumpf ≫ Trutops Cell Sw48 Version >= 01.00 <= 02.26.0
Trumpf ≫ Trutops Mark 3d Version >= 01.00 <= 06.01
Trumpf ≫ Trutopsboost Version >= 06.00.23.00 <= 16.0.22
Trumpf ≫ Trutopsfab Version >= 15.00.23.00 <= 22.8.25
Trumpf ≫ Trutopsfab Storage Smallstore Version >= 14.06.20 <= 20.04.20.00
Trumpf ≫ Trutopsprint Version >= 00.06.00 <= 01.00
Trumpf ≫ Trutopsweld Version >= 7.0.198.241 <= 9.0.28148.1
Trumpf ≫ Tubedesign Version >= 08.00 <= 14.06.150
Phoenixcontact ≫ Activation Wizard SwPlatform moryx Version <= 1.6
Phoenixcontact ≫ Iol-conf Version <= 1.7.0
Phoenixcontact ≫ Module Type Package Designer Version 1.2.0 Update beta
Phoenixcontact ≫ Plcnext Engineer Version <= 2023.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.49% 0.719
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
info@cert.vde.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-230704-01-v3.0.pdf
Vendor Advisory
https://cert.vde.com/en/advisories/VDE-2023-030/
Third Party Advisory
https://cert.vde.com/en/advisories/VDE-2023-031/
Third Party Advisory