CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
AI Score
Confidence
High
EPSS
Percentile
32.1%
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different toย CVE-2023-37552,ย CVE-2023-37553,ย CVE-2023-37554 andย CVE-2023-37556.
Vendor | Product | Version | CPE |
---|---|---|---|
codesys | control_for_beaglebone_sl | * | cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:* |
codesys | control_for_empc-a\/imx6_sl | * | cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:* |
codesys | control_for_iot2000_sl | * | cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:* |
codesys | control_for_linux_sl | * | cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:* |
codesys | control_for_pfc100_sl | * | cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:* |
codesys | control_for_pfc200_sl | * | cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:* |
codesys | control_for_plcnext_sl | * | cpe:2.3:a:codesys:control_for_plcnext_sl:*:*:*:*:*:*:*:* |
codesys | control_for_raspberry_pi_sl | * | cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:* |
codesys | control_for_wago_touch_panels_600_sl | * | cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:* |
codesys | control_rte_sl | * | cpe:2.3:a:codesys:control_rte_sl:*:*:*:*:*:*:*:* |
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
AI Score
Confidence
High
EPSS
Percentile
32.1%