Input validation error in CODESYS products - CVE-2023-37558
Published: April 7, 2025
Vulnerability identifier: #VU107040
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-37558
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: CODESYS
Affected software:
CODESYS Control for BeagleBone SL
CODESYS Control for emPC-A/iMX6 SL
CODESYS Control for IOT2000 SL
CODESYS Control for Linux SL
CODESYS Control for PFC100 SL
CODESYS Control for PFC200 SL
CODESYS Control for PLCnext SL
CODESYS Control for Raspberry Pi SL
CODESYS Control for WAGO Touch Panels 600 SL
CODESYS Control Runtime System Toolkit
CODESYS Development System V3
CODESYS Safety SIL2 Runtime Toolkit
CODESYS Control RTE (for Beckhoff CX) SL
CODESYS Control RTE (SL)
CODESYS Control Win (SL)
CODESYS HMI (SL)
CODESYS Control for BeagleBone SL
CODESYS Control for emPC-A/iMX6 SL
CODESYS Control for IOT2000 SL
CODESYS Control for Linux SL
CODESYS Control for PFC100 SL
CODESYS Control for PFC200 SL
CODESYS Control for PLCnext SL
CODESYS Control for Raspberry Pi SL
CODESYS Control for WAGO Touch Panels 600 SL
CODESYS Control Runtime System Toolkit
CODESYS Development System V3
CODESYS Safety SIL2 Runtime Toolkit
CODESYS Control RTE (for Beckhoff CX) SL
CODESYS Control RTE (SL)
CODESYS Control Win (SL)
CODESYS HMI (SL)
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the CmpAppForce component. A remote user can pass specially crafted input to the application and perform a denial of service (DoS) attack.
How to mitigate CVE-2023-37558
Install updates from vendor's website.