CVE-2023-37551 - Files or Directories Accessible to External Parties

Severity

65%

Complexity

27%

Confidentiality

60%

In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communication requests can utilize the CmpApp component to download files with any file extensions to the controller. In contrast to the regular file download via CmpFileTransfer, no filtering of certain file types is performed here. As a result, the integrity of the CODESYS control runtime system may be compromised by the files loaded onto the controller.

CVSS 3.1 Base Score 6.5. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).

Overview

Type

CODESYS

First reported 1 year ago

2023-08-03 12:15:00

Last updated 1 year ago

2023-08-08 15:42:00

Affected Software

CODESYS Safety SIL2

CODESYS HMI

CODESYS Control Runtime System Toolkit

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.