Missing Integrity Check in CODESYS Notification Server Allows Remote Content Manipulation

Missing Integrity Check in CODESYS Notification Server Allows Remote Content Manipulation

CVE-2023-3663 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to manipulate the content of notifications received via HTTP by the CODESYS notification server.

Learn more about our Cis Benchmark Audit For Server Software.