A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
References
| Link | Resource |
|---|---|
| https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-230704-01-v3.0.pdf | Vendor Advisory |
| https://cert.vde.com/en/advisories/VDE-2023-030/ | Third Party Advisory |
| https://cert.vde.com/en/advisories/VDE-2023-031/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
25 Jan 2024, 20:24
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Phoenixcontact fl Network Manager
Phoenixcontact Phoenixcontact activation Wizard Phoenixcontact e-mobility Charging Suite Phoenixcontact module Type Package Designer Phoenixcontact iol-conf Phoenixcontact plcnext Engineer |
|
| CPE | cpe:2.3:a:phoenixcontact:iol-conf:*:*:*:*:*:*:*:* cpe:2.3:a:phoenixcontact:e-mobility_charging_suite:*:*:*:*:*:*:*:* cpe:2.3:a:phoenixcontact:module_type_package_designer:1.2.0:beta:*:*:*:*:*:* cpe:2.3:a:phoenixcontact:fl_network_manager:*:*:*:*:*:*:*:* cpe:2.3:a:phoenixcontact:activation_wizard:*:*:*:*:*:moryx:*:* cpe:2.3:a:phoenixcontact:plcnext_engineer:*:*:*:*:*:*:*:* cpe:2.3:a:phoenixcontact:module_type_package_designer:*:*:*:*:*:*:*:* |
|
| References | () https://cert.vde.com/en/advisories/VDE-2023-030/ - Third Party Advisory |
Information
Published : 2023-09-13 14:15
Updated : 2024-01-25 20:24
NVD link : CVE-2023-3935
Mitre link : CVE-2023-3935
CVE.ORG link : CVE-2023-3935
JSON object : View
Products Affected
trumpf
- oseon
- trutopsprintmultilaserassistant
- trutopsfab_storage_smallstore
- trutops_cell_sw48
- trutopsweld
- trutopsfab
- trutops_cell_classic
- trutops
- trutopsboost
- teczonebend
- programmingtube
- tops_unfold
- topscalculation
- tubedesign
- trutops_mark_3d
- trutopsprint
- trumpflicenseexpert
phoenixcontact
- module_type_package_designer
- activation_wizard
- e-mobility_charging_suite
- iol-conf
- plcnext_engineer
- fl_network_manager
wibu
- codemeter_runtime
CWE
CWE-787
Out-of-bounds Write
