Summary
The Notification Center of the CODESYS Development System receives messages without ensuring that the message was not modified during transmission. This finally enables MITMs code execution when the user clicks the "Learn More" button.
Impact
Affected Product(s)
| Model no. | Product name | Affected versions | 
|---|---|---|
| CODESYS Development System 3.5.11.0<3.5.19.20 | CODESYS Development System 3.5.11.0<3.5.19.20 | 
Vulnerabilities
Expand / Collapse allIn CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to manipulate the content of notifications received via HTTP by the CODESYS notification server.
Remediation
Update the CODESYS Development System to version 3.5.19.20.
The CODESYS Development System can be downloaded and installed directly with the CODESYS Installer or be downloaded from the CODESYS Store.
Alternatively, you will find further information on obtaining the software update in the CODESYS Update area
Acknowledgments
CODESYS GmbH thanks the following parties for their efforts:
- CERT@VDE for coordination (see https://certvde.com )
- Sina Kheirkhah from SinSinology working with Trend Micro Zero Day Initiative for reporting
Revision History
| Version | Date | Summary | 
|---|---|---|
| 1 | 03.08.2023 12:52 | Initial revision. |