CVE-2023-3669
published 2023-08-03CVE-2023-3669: A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimited attempts of guessing the password…
PriorityP411low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.14%
3.8th percentile
A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimited attempts of guessing the password within an import dialog.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| codesys | codesys_development_system | >= 3.0.0.0 < 3.5.19.20 | 3.5.19.20 |
| codesys | development_system | < 3.5.19.20 | 3.5.19.20 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
CODESYS in Festo Automation Suite
cisa_ics·2026-03-17
CODESYS in Festo Automation Suite
ICS Advisory
##
CODESYS in Festo Automation Suite
Release DateMarch 17, 2026
Alert CodeICSA-26-076-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
3. TECHNICAL DETAILS
The following versions of CODESYS in Festo Automation Suite are affected:
- FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0) vers:all/*
- FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10) vers:all/*
- FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0) vers:all/*
- FESTO Software Festo Automation
CISA ICS
Schneider Electric devices using CODESYS Runtime
cisa_ics·2026-01-20·CVSS 8.8
[HIGH] Schneider Electric devices using CODESYS Runtime
ICS Advisory
##
Schneider Electric devices using CODESYS Runtime
Release DateJanuary 20, 2026
Alert CodeICSA-26-020-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Schneider Electric is aware of multiple vulnerabilities disclosed on CODESYS runtime system V3 communication server. Many vendors, including Schneider Electric, embed CODESYS in their offers. If successfully exploited, these vulnerabilities could result in a denial of service or, in some cases, in remote code execution on PacDrive controllers, Modicon Controllers M241 / M251 / M262 / M258 / LMC058 / LMC078 / M218 , HMISCU, the Simulation Runtime SoftSPS from EcoStruxure Machine Expert and EcoStruxure Microgrid Operation products. Failure
CISA ICS
CODESYS Development System
cisa_ics·2023-08-24·CVSS 3.3
[LOW] CODESYS Development System
ICS Advisory
##
CODESYS Development System
Release DateAugust 24, 2023
Alert CodeICSA-23-236-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 3.3
- ATTENTION: low attack complexity
- Vendor: CODESYS, GmbH
- Equipment: CODESYS Development System
- Vulnerability: Improper Restriction of Excessive Authentication Attempts.
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could provide a local attacker with account information.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
CODESYS reports this vulnerability affects the following versions of CODESYS Development System:
- CODESYS Development System: versions prior to 3.5.19.20
## 3.2 VULNERABILITY OVERVIEW
3.2.1 INSUFFICIENT VERIFICATION OF DATA AUTHENTICITY CWE-345
A missing brute-force protectio
GHSA
GHSA-gwpm-jp9f-hxfg: A missing Brute-Force protection in CODESYS Development System prior to 3
ghsa_unreviewed·2023-08-03
CVE-2023-3669 [LOW] CWE-307 GHSA-gwpm-jp9f-hxfg: A missing Brute-Force protection in CODESYS Development System prior to 3
A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimited attempts of guessing the password within an import dialog.
OSV
linux-snapdragon vulnerabilities
osv·2023-04-19·CVSS 5.5
CVE-2023-1281 linux-snapdragon vulnerabilities
linux-snapdragon vulnerabilities
It was discovered that the Traffic-Control Index (TCINDEX) implementation
in the Linux kernel contained a use-after-free vulnerability. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2023-1281)
It was discovered that the System V IPC implementation in the Linux kernel
did not properly handle large shared memory counts. A local attacker could
use this to cause a denial of service (memory exhaustion). (CVE-2021-3669)
It was discovered that a use-after-free vulnerability existed in the SGI
GRU driver in the Linux kernel. A local attacker could possibly use this to
cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2022-3424)
Ziming Zhang discovered that the
OSV
linux-azure-4.15 vulnerabilities
osv·2023-03-07·CVSS 5.5
CVE-2023-0461 linux-azure-4.15 vulnerabilities
linux-azure-4.15 vulnerabilities
It was discovered that the Upper Level Protocol (ULP) subsystem in the
Linux kernel did not properly handle sockets entering the LISTEN state in
certain protocols, leading to a use-after-free vulnerability. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2023-0461)
It was discovered that the System V IPC implementation in the Linux kernel
did not properly handle large shared memory counts. A local attacker could
use this to cause a denial of service (memory exhaustion). (CVE-2021-3669)
It was discovered that a use-after-free vulnerability existed in the SGI
GRU driver in the Linux kernel. A local attacker could possibly use this to
cause a denial of service (system crash) or possibly ex
OSV
linux-azure, linux-azure, linux-azure vulnerabilities
osv·2023-03-06·CVSS 5.5
CVE-2023-0461 linux-azure, linux-azure, linux-azure vulnerabilities
linux-azure, linux-azure, linux-azure vulnerabilities
It was discovered that the Upper Level Protocol (ULP) subsystem in the
Linux kernel did not properly handle sockets entering the LISTEN state in
certain protocols, leading to a use-after-free vulnerability. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2023-0461)
It was discovered that the System V IPC implementation in the Linux kernel
did not properly handle large shared memory counts. A local attacker could
use this to cause a denial of service (memory exhaustion). (CVE-2021-3669)
It was discovered that an out-of-bounds write vulnerability existed in the
Video for Linux 2 (V4L2) implementation in the Linux kernel. A local
attacker could use this to cause a deni
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-08-03
Published