CVE-2023-3935
published 2023-09-13CVE-2023-3935: A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE…
PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.50%
71.4th percentile
A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phoenixcontact | activation_wizard | <= 1.6 | — |
| phoenixcontact | e-mobility_charging_suite | <= 1.7.0 | — |
| phoenixcontact | fl_network_manager | <= 7.0 | — |
| phoenixcontact | iol-conf | <= 1.7.0 | — |
| phoenixcontact | module_type_package_designer | < 1.2.0 | 1.2.0 |
| phoenixcontact | module_type_package_designer | — | — |
| phoenixcontact | plcnext_engineer | <= 2023.6 | — |
| trumpf | oseon | 1.0.0 – 3.0.22 | — |
| trumpf | programmingtube | 1.0.1 – 4.6.3 | — |
| trumpf | teczonebend | 18.02.r8 – 23.06.01 | — |
| trumpf | tops_unfold | — | — |
| trumpf | topscalculation | 14.00 – 22.00.00 | — |
| trumpf | trumpflicenseexpert | 1.5.2 – 1.11.1 | — |
| trumpf | trutops | 08.00 – 12.01.00.00 | — |
| trumpf | trutops_cell_classic | <= 09.09.02 | — |
| trumpf | trutops_cell_sw48 | 01.00 – 02.26.0 | — |
| trumpf | trutops_mark_3d | 01.00 – 06.01 | — |
| trumpf | trutopsboost | 06.00.23.00 – 16.0.22 | — |
| trumpf | trutopsfab | 15.00.23.00 – 22.8.25 | — |
| trumpf | trutopsfab_storage_smallstore | 14.06.20 – 20.04.20.00 | — |
| trumpf | trutopsprint | 00.06.00 – 01.00 | — |
| trumpf | trutopsprintmultilaserassistant | >= 01.02 | — |
| trumpf | trutopsweld | 7.0.198.241 – 9.0.28148.1 | — |
| trumpf | tubedesign | 08.00 – 14.06.150 | — |
| wibu | codemeter_runtime | < 7.60c | 7.60c |
Detection & IOCsextracted from sources · hover to see the quote
- →Remote exploitation is only possible when CodeMeter Runtime is configured as a network server; if configured as client-only, attack requires local access or user interaction ↗
- →The vulnerable process is CodeMeter.exe (CodeMeter Runtime network service); monitor for crashes or anomalous behavior of this process as an indicator of exploitation attempts ↗
- →No public PoC is known; exploitation requires breaking additional protection mechanisms beyond the heap overflow itself, raising the bar for successful RCE ↗
- →Affected versions are CodeMeter Runtime up to and including 7.60b; version 7.60c and later are patched — use version enumeration to identify vulnerable instances on the network ↗
- →Rockwell Automation FactoryTalk Activation Manager V4.00 utilizes Wibu-Systems CodeMeter <7.60c and is a specific vulnerable product instance to scan for ↗
- ·Attack surface is conditional: remote unauthenticated RCE is only possible when CodeMeter Runtime is explicitly configured as a server; client-only deployments require local access or social engineering ↗
- ·High attack complexity is noted in the CVSS vector (AC:H), meaning exploitation requires breaking additional protection mechanisms beyond the heap overflow ↗
- ·No known public exploitation of this vulnerability has been reported at time of advisory publication ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
CODESYS in Festo Automation Suite
cisa_ics·2026-03-17
CODESYS in Festo Automation Suite
ICS Advisory
##
CODESYS in Festo Automation Suite
Release DateMarch 17, 2026
Alert CodeICSA-26-076-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
3. TECHNICAL DETAILS
The following versions of CODESYS in Festo Automation Suite are affected:
- FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0) vers:all/*
- FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10) vers:all/*
- FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0) vers:all/*
- FESTO Software Festo Automation
CISA ICS
Rockwell Automation FactoryTalk Activation
cisa_ics·2024-01-04·CVSS 9.8
[CRITICAL] Rockwell Automation FactoryTalk Activation
ICS Advisory
##
Rockwell Automation FactoryTalk Activation
Release DateJanuary 04, 2024
Alert CodeICSA-24-004-01
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Rockwell Automation
- Equipment: FactoryTalk Activation Manager
- Vulnerabilities: Out-of-Bounds Write
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in a buffer overflow and allow the attacker to gain full access to the system.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Factory Talk are affected:
- Factory Talk: V4.00 (Utilizes Wibu-Systems CodeMeter <7.60c)
## 3.2 Vulnerability Overview
3.2.1 OUT-OF-BOUNDS WRITE CWE-787
Rockwell Automation FactoryTalk Activ
CISA ICS
Siemens Desigo CC product family
cisa_ics·2023-11-16·CVSS 9.1
[CRITICAL] Siemens Desigo CC product family
ICS Advisory
##
Siemens Desigo CC product family
Release DateNovember 16, 2023
Alert CodeICSA-23-320-03
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.1
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Siemens
- Equipment: Desigo CC product family
- Vulnerabilities: Buffer Over-Read, Heap-Based Buffer Overflow
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow remote attackers to execute arbitrary c
CISA ICS
Siemens WIBU Systems CodeMeter
cisa_ics·2023-09-14
Siemens WIBU Systems CodeMeter
ICS Advisory
##
Siemens WIBU Systems CodeMeter
Release DateSeptember 14, 2023
Alert CodeICSA-23-257-06
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.0
- ATTENTION: Exploitable remotely
- Vendor: Siemens
- Equipment: WIBU Systems CodeMeter
- Vulnerability: Heap-Based Buffer Overflow
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an unauthenticated attacker to escalate privileges or execute arbitrary code.
##
GHSA
GHSA-c9rf-qf73-r46f: A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7
ghsa_unreviewed·2023-09-13
CVE-2023-3935 CWE-787 GHSA-c9rf-qf73-r46f: A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7
A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-230704-01-v3.0.pdfhttps://cert.vde.com/en/advisories/VDE-2023-030/https://cert.vde.com/en/advisories/VDE-2023-031/https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-230704-01-v3.0.pdfhttps://cert.vde.com/en/advisories/VDE-2023-030/https://cert.vde.com/en/advisories/VDE-2023-031/
2023-09-13
Published