HIGH🇵🇱 Wersja polska

CVE-2023-6357

CVSS 8.8v3.1pub. 2023-12-05upd. 2024-11-21

A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Codesys Control For Beaglebone Sl

    APP
    Codesys
    < 4.11.0.0
  • Codesys Control For Empc A\/imx6

    APP
    Codesys
    < 4.11.0.0
  • Codesys Control For Iot2000 Sl

    APP
    Codesys
    < 4.11.0.0
  • Codesys Control For Linux Arm Sl

    APP
    Codesys
    < 4.11.0.0
  • Codesys Control For Linux Sl

    APP
    Codesys
    < 4.11.0.0
  • Codesys Control For Pfc100 Sl

    APP
    Codesys
    < 4.11.0.0
  • Codesys Control For Pfc200 Sl

    APP
    Codesys
    < 4.11.0.0
  • Codesys Control For Plcnext Sl

    APP
    Codesys
    < 4.11.0.0
  • Codesys Control For Raspberry Pi Sl

    APP
    Codesys
    < 4.11.0.0
  • Codesys Control For Wago Touch Panels 600 Sl

    APP
    Codesys
    < 4.11.0.0
  • Codesys Runtime Toolkit

    APP
    Codesys
    < 3.5.19.50
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2022-31806CRITICAL9.8PL ✓same product

CODESYS V2 PLCWinNT/Runtime Toolkit — brak domyślnego hasła na kontrolerze

CVE-2020-10245CRITICAL9.8PL ✓same product

Buffer overflow w serwerze web CODESYS V3 umożliwiający RCE

CVE-2019-18858CRITICAL9.8PL ✓same product

Buffer Overflow w serwerze WWW CODESYS 3 — zdalne wykonanie kodu

CVE-2019-13548CRITICAL9.8PL ✓same product

Stack overflow w CODESYS V3 web server umożliwiający RCE

CVE-2019-9010CRITICAL9.8PL ✓same product

CODESYS Gateway V3 — błędna weryfikacja właściciela kanału komunikacyjnego