SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-3935

A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.

CRITICAL 9.8EPSS 1.97%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.97%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.97% probability · 79th percentile
CISA KEV
Not listed
Weakness
CWE-787
Affected
wibu/codemeter runtime · trumpf/oseon · trumpf/programmingtube · trumpf/teczonebend · trumpf/tops unfold · trumpf/topscalculation · trumpf/trumpflicenseexpert · trumpf/trutops · trumpf/trutops cell classic · trumpf/trutops cell sw48 · trumpf/trutops mark 3d · trumpf/trutopsboost · trumpf/trutopsfab · trumpf/trutopsfab storage smallstore · trumpf/trutopsprint · trumpf/trutopsprintmultilaserassistant · trumpf/trutopsweld · trumpf/tubedesign · phoenixcontact/activation wizard · phoenixcontact/e-mobility charging suite · +4 more
Source
info@cert.vde.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.