Medium severity6.5NVD Advisory· Published Aug 3, 2023· Updated Jun 17, 2026
CVE-2023-37559
CVE-2023-37559
Description
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37558
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
19- cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:*Range: <4.10.0.0
- cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:*Range: <4.10.0.0
cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*range: <4.10.0.0
- cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:*range: <4.10.0.0
- cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:*Range: <4.10.0.0
- cpe:2.3:a:codesys:control_for_plcnext_sl:*:*:*:*:*:*:*:*Range: <4.10.0.0
cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*range: <4.10.0.0
- (no CPE)range: 0
- cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:*Range: <4.10.0.0
- cpe:2.3:a:codesys:control_rte_sl_\(for_beckhoff_cx\):*:*:*:*:*:*:*:*Range: <3.5.19.20
- cpe:2.3:a:codesys:control_runtime_system_toolkit:*:*:*:*:*:*:*:*Range: <3.5.19.20
Patches
Vulnerability mechanics
References
1- cert.vde.com/en/advisories/VDE-2023-019/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.