CODESYS Files or Directories Accessible to External Parties in CmpApp
CVE-2023-37551

6.5MEDIUM

What is CVE-2023-37551?

In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communication requests can utilize the CmpApp component to download files with any file extensions to the controller. In contrast to the regular file download via CmpFileTransfer, no filtering of certain file types is performed here. As a result, the integrity of the CODESYS control runtime system may be compromised by the files loaded onto the controller.

Affected Version(s)

CODESYS Control for BeagleBone SL 0

CODESYS Control for emPC-A/iMX6 SL 0

CODESYS Control for IOT2000 SL 0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vladimir Tokarev, Section 52, Azure IoT Security at Microsoft
.