After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://cert.vde.com/en/advisories/VDE-2023-019/ | third party advisory |