Back

MEDIUM

CODESYS Improper Input Validation in CmpAppBP

Published Aug 3, 2023

Description

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37553, CVE-2023-37554, CVE-2023-37555 and CVE-2023-37556.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CERTVDE
Published Aug 3, 2023
Updated Oct 11, 2024
Reserved Jul 7, 2023
CISA Vulnrichment
Updated Oct 11, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner CERTVDE
Published Aug 3, 2023
Updated Oct 11, 2024
Exploited since n/a
EUVD-2023-41438