Vulnerabilities > CVE-2023-3670 - Exposure of Resource to Wrong Sphere vulnerability in Codesys Development System and Scripting

047910
CVSS 7.3 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
codesys
CWE-668

Summary

In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.

Vulnerable Configurations

Part Description Count
Application
Codesys
55

Common Weakness Enumeration (CWE)