IM
IronMonkey Threat Research

CVE-2023-3670 HIGH

Published: 2023-07-28 | Last Modified: 2024-11-21 | Status: Modified

Description

In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.

CVSS Metrics

Base Score: 7.3 (HIGH)

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionREQUIRED
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Secondary

Exploitability Score: 1.3

Impact Score: 5.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-668

Affected Products

Vendor Product Version Update Type
codesys development_system * <built-in method update of dict object at 0x7e61114e0f80> Application
codesys scripting * <built-in method update of dict object at 0x7e60e8c7d9c0> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:codesys:development_system:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:codesys:scripting:*:*:*:*:*:*:*:*

References

Notification
Message here