Unauthenticated Local Attackers Can Trick Users to Execute Arbitrary Code or Crash System
CVE-2023-49675

7.8HIGH

Key Information:

Vendor

Codesys

Vendor
CVE Published:
6 May 2024

What is CVE-2023-49675?

An out-of-bounds write vulnerability exists within the affected vendor's product that can be exploited by an unauthenticated local attacker. The attacker can trick a user into opening corrupted project files, which may lead to the execution of arbitrary code or cause the system to crash. This vulnerability poses significant risks as it can disrupt services and lead to unauthorized actions on the affected systems.

Affected Version(s)

CODESYS Development System V2.3 0 < 2.3.9.73

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl
.