VulnerabilityModified
CVE-2023-3935
A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
CRITICAL 9.8EPSS 1.97%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.97%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.97% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- wibu/codemeter runtime · trumpf/oseon · trumpf/programmingtube · trumpf/teczonebend · trumpf/tops unfold · trumpf/topscalculation · trumpf/trumpflicenseexpert · trumpf/trutops · trumpf/trutops cell classic · trumpf/trutops cell sw48 · trumpf/trutops mark 3d · trumpf/trutopsboost · trumpf/trutopsfab · trumpf/trutopsfab storage smallstore · trumpf/trutopsprint · trumpf/trutopsprintmultilaserassistant · trumpf/trutopsweld · trumpf/tubedesign · phoenixcontact/activation wizard · phoenixcontact/e-mobility charging suite · +4 more
- Source
- info@cert.vde.com
References
- https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-230704-01-v3.0.pdfVendor Advisory
- https://cert.vde.com/en/advisories/VDE-2023-030/Third Party Advisory
- https://cert.vde.com/en/advisories/VDE-2023-031/Third Party Advisory
- https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-230704-01-v3.0.pdfVendor Advisory
- https://cert.vde.com/en/advisories/VDE-2023-030/Third Party Advisory
- https://cert.vde.com/en/advisories/VDE-2023-031/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.