CVE-2023-3670

In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.
References
Link Resource
https://cert.vde.com/en/advisories/VDE-2023-024 Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:codesys:development_system:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:scripting:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-07-28 08:15

Updated : 2023-08-03 18:44


NVD link : CVE-2023-3670

Mitre link : CVE-2023-3670

CVE.ORG link : CVE-2023-3670


JSON object : View

Products Affected

codesys

  • development_system
  • scripting
CWE
CWE-668

Exposure of Resource to Wrong Sphere