CVE-2023-3670
Last modified
CVE-2023-3670 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Codesys | Development System | >= 3.5.9.0, < 3.5.17.0 |
| Codesys | Scripting | >= 4.0.0.0, < 4.1.0.0 |
References
- https://cert.vde.com/en/advisories/VDE-2023-024Third Party Advisory
- https://cert.vde.com/en/advisories/VDE-2023-024Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-3670?
How severe is CVE-2023-3670?
How do I fix CVE-2023-3670?
Are you affected by CVE-2023-3670?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
