cbcvebase.
CVE-2023-3935
published 2023-09-13

CVE-2023-3935: A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE…

PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.50%
71.4th percentile
A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
phoenixcontactactivation_wizard<= 1.6
phoenixcontacte-mobility_charging_suite<= 1.7.0
phoenixcontactfl_network_manager<= 7.0
phoenixcontactiol-conf<= 1.7.0
phoenixcontactmodule_type_package_designer< 1.2.01.2.0
phoenixcontactmodule_type_package_designer
phoenixcontactplcnext_engineer<= 2023.6
trumpfoseon1.0.0 – 3.0.22
trumpfprogrammingtube1.0.1 – 4.6.3
trumpfteczonebend18.02.r8 – 23.06.01
trumpftops_unfold
trumpftopscalculation14.00 – 22.00.00
trumpftrumpflicenseexpert1.5.2 – 1.11.1
trumpftrutops08.00 – 12.01.00.00
trumpftrutops_cell_classic<= 09.09.02
trumpftrutops_cell_sw4801.00 – 02.26.0
trumpftrutops_mark_3d01.00 – 06.01
trumpftrutopsboost06.00.23.00 – 16.0.22
trumpftrutopsfab15.00.23.00 – 22.8.25
trumpftrutopsfab_storage_smallstore14.06.20 – 20.04.20.00
trumpftrutopsprint00.06.00 – 01.00
trumpftrutopsprintmultilaserassistant>= 01.02
trumpftrutopsweld7.0.198.241 – 9.0.28148.1
trumpftubedesign08.00 – 14.06.150
wibucodemeter_runtime< 7.60c7.60c

Detection & IOCsextracted from sources · hover to see the quote

  • Remote exploitation is only possible when CodeMeter Runtime is configured as a network server; if configured as client-only, attack requires local access or user interaction
  • The vulnerable process is CodeMeter.exe (CodeMeter Runtime network service); monitor for crashes or anomalous behavior of this process as an indicator of exploitation attempts
  • No public PoC is known; exploitation requires breaking additional protection mechanisms beyond the heap overflow itself, raising the bar for successful RCE
  • Affected versions are CodeMeter Runtime up to and including 7.60b; version 7.60c and later are patched — use version enumeration to identify vulnerable instances on the network
  • Rockwell Automation FactoryTalk Activation Manager V4.00 utilizes Wibu-Systems CodeMeter <7.60c and is a specific vulnerable product instance to scan for
  • ·Attack surface is conditional: remote unauthenticated RCE is only possible when CodeMeter Runtime is explicitly configured as a server; client-only deployments require local access or social engineering
  • ·High attack complexity is noted in the CVSS vector (AC:H), meaning exploitation requires breaking additional protection mechanisms beyond the heap overflow
  • ·No known public exploitation of this vulnerability has been reported at time of advisory publication
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.