CVE-2023-3663: high-severity vulnerability in CODESYS Development System
CODESYS: Missing integrity check in CODESYS Development System
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.8epss 1.0%
exploitation probability
1.0%top 38% of all CVEs
observed exploitation
nono source reports it
In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to manipulate the content of notifications received via HTTP by the CODESYS notification server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
CODESYS · CODESYS Development SystemRelated CVEs — CODESYS Development System
In the same product, most dangerous first.
CVE-2022-31805HIGHInsecure transmission of credentialsEPSS 1.0%CVE-2023-3662HIGHCODESYS: Vulnerability in CODESYS Development System allows for execution of binariesEPSS 0.2%CVE-2023-3670HIGHCodesys: Vulnerability in CODESYS Development System and CODESYS ScriptingEPSS 0.2%CVE-2025-41700HIGHCODESYS Development System - Deserialization of Untrusted DataEPSS 0.2%CVE-2023-3669LOWCODESYS: Missing Brute-Force protection in CODESYS Development SystemEPSS 0.1%CVE-2026-44468HIGHIncorrect Default Permissions in CODESYS Development SystemEPSS 0.1%