CVE-2023-3935

A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CERTVDECNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 61%
VendorProductVersion
wibucodemeter_runtime
𝑥
< 7.60c
trumpfoseon
1.0.0 ≤
𝑥
≤ 3.0.22
trumpfprogrammingtube
1.0.1 ≤
𝑥
≤ 4.6.3
trumpfteczonebend
18.02.r8 ≤
𝑥
≤ 23.06.01
trumpftops_unfold
05.03.00.00
trumpftopscalculation
14.00 ≤
𝑥
≤ 22.00.00
trumpftrumpflicenseexpert
1.5.2 ≤
𝑥
≤ 1.11.1
trumpftrutops
08.00 ≤
𝑥
≤ 12.01.00.00
trumpftrutops_cell_classic
𝑥
≤ 09.09.02
trumpftrutops_cell_sw48
01.00 ≤
𝑥
≤ 02.26.0
trumpftrutops_mark_3d
01.00 ≤
𝑥
≤ 06.01
trumpftrutopsboost
06.00.23.00 ≤
𝑥
≤ 16.0.22
trumpftrutopsfab
15.00.23.00 ≤
𝑥
≤ 22.8.25
trumpftrutopsfab_storage_smallstore
14.06.20 ≤
𝑥
≤ 20.04.20.00
trumpftrutopsprint
00.06.00 ≤
𝑥
≤ 01.00
trumpftrutopsprintmultilaserassistant
01.02 ≤
trumpftrutopsweld
7.0.198.241 ≤
𝑥
≤ 9.0.28148.1
trumpftubedesign
08.00 ≤
𝑥
≤ 14.06.150
phoenixcontactactivation_wizard
𝑥
≤ 1.6
phoenixcontacte-mobility_charging_suite
𝑥
≤ 1.7.0
phoenixcontactfl_network_manager
𝑥
≤ 7.0
phoenixcontactiol-conf
𝑥
≤ 1.7.0
phoenixcontactmodule_type_package_designer
𝑥
< 1.2.0
phoenixcontactmodule_type_package_designer
1.2.0:beta
phoenixcontactplcnext_engineer
𝑥
≤ 2023.6
𝑥
= Vulnerable software versions