CVE-2023-37547

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546, CVE-2023-37548, CVE-2023-37549 and CVE-2023-37550
References
Link Resource
https://cert.vde.com/en/advisories/VDE-2023-019 Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_plcnext_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:codesys:control_rte_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_sl_\(for_beckhoff_cx\):*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_runtime_system_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_win_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:development_system:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:hmi:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:safety_sil2:*:*:*:*:*:*:*:*

History

07 Aug 2023, 19:29

Type Values Removed Values Added
First Time Codesys control For Empc-a\/imx6 Sl
Codesys control Runtime System Toolkit
Codesys control For Wago Touch Panels 600 Sl
Codesys control Rte Sl
Codesys control For Pfc100 Sl
Codesys hmi
Codesys control Win Sl
Codesys control Rte Sl \(for Beckhoff Cx\)
Codesys control For Beaglebone Sl
Codesys
Codesys control For Pfc200 Sl
Codesys control For Raspberry Pi Sl
Codesys control For Iot2000 Sl
Codesys control For Plcnext Sl
Codesys control For Linux Sl
Codesys development System
Codesys safety Sil2
CPE cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_runtime_system_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:safety_sil2:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:hmi:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_sl_\(for_beckhoff_cx\):*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_plcnext_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_win_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:development_system:*:*:*:*:*:*:*:*
CWE CWE-20 NVD-CWE-noinfo
References (MISC) https://cert.vde.com/en/advisories/VDE-2023-019 - (MISC) https://cert.vde.com/en/advisories/VDE-2023-019 - Third Party Advisory

03 Aug 2023, 12:40

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-03 12:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-37547

Mitre link : CVE-2023-37547

CVE.ORG link : CVE-2023-37547


JSON object : View

Products Affected

codesys

  • control_for_raspberry_pi_sl
  • control_for_empc-a\/imx6_sl
  • control_for_pfc100_sl
  • control_runtime_system_toolkit
  • safety_sil2
  • control_rte_sl_\(for_beckhoff_cx\)
  • control_for_linux_sl
  • control_rte_sl
  • control_for_wago_touch_panels_600_sl
  • hmi
  • control_for_pfc200_sl
  • control_for_iot2000_sl
  • development_system
  • control_for_plcnext_sl
  • control_for_beaglebone_sl
  • control_win_sl
CWE
NVD-CWE-noinfo CWE-20

Improper Input Validation