cbcvebase.
CVE-2023-3663
published 2023-08-03

CVE-2023-3663: In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to…

PriorityP354high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.03%
59.8th percentile
In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to manipulate the content of notifications received via HTTP by the CODESYS notification server.

Affected

2 ranges
VendorProductVersion rangeFixed in
codesyscodesys_development_system>= 3.5.11.20 < 3.5.19.203.5.19.20
codesysdevelopment_system>= 3.5.11.20 < 3.5.19.203.5.19.20
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.