Unauthenticated Local Attackers Can Trick Users to Execute Arbitrary Code or Crash System
CVE-2023-49675

7.8HIGH

Key Information:

Vendor

Codesys

Vendor
CVE Published:
6 May 2024

What is CVE-2023-49675?

An out-of-bounds write vulnerability exists within the affected vendor's product that can be exploited by an unauthenticated local attacker. The attacker can trick a user into opening corrupted project files, which may lead to the execution of arbitrary code or cause the system to crash. This vulnerability poses significant risks as it can disrupt services and lead to unauthorized actions on the affected systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

CODESYS Development System V2.3 0 < 2.3.9.73

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl
.