← Vulnerability feed

Vulnerability record · CVE-2023-3663 · published 3 August 2023

CVE-2023-3663: Codesys development system vulnerability

Codesys · Development System

In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to manipulate the content of notifications received via HTTP by the CODESYS notification server.

8.8 CVSS 3.1 High EPSS 1.0% · top 38.0% CWE-940 · CWE-940
8.8CVSS 3.1 base score
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to manipulate the content of notifications received via HTTP by the CODESYS notification server.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-3663 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-9010Codesys control for beaglebone sl vulnerabilityAn issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of a communication channel. All …EPSS 1.9%8.8CVE-2022-4224Codesys control for beaglebone sl insecure default initialization vulnerabilityIn multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files…EPSS 0.88%8.8CVE-2019-9013Codesys control for beaglebone sl broken cryptographic algorithm vulnerabilityAn issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials bein…EPSS 0.28%8.5CVE-2026-44469Codesys development system incorrect default permissions vulnerabilityThe affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A lo…EPSS 0.12%8.5CVE-2026-44468Codesys development system incorrect default permissions vulnerabilityThe affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local att…EPSS 0.14%8.1CVE-2022-22515Codesys control for beaglebone sl exposure of resource to wrong sphere vulnerabilityA remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read an…EPSS 1.1%7.8CVE-2022-22516Codesys control rte sl incorrect permission assignment vulnerabilityThe SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory spac…EPSS 0.26%7.8CVE-2021-21863Codesys development system deserialization of untrusted data vulnerabilityA unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.1…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2023-3663), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.