CVE-2023-37551 | CODESYS Files or Directories Accessible to External Parties in CmpApp

In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communication requests can utilize the CmpApp component to download files with any file extensions to the controller. In contrast to the regular file download via CmpFileTransfer, no filtering of certain file types is performed here. As a result, the integrity of the CODESYS control runtime system may be compromised by the files loaded onto the controller.

Published: 2023-08-03 Last update: 2024-11-21 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2023-37551 is rated Low Risk (32.7/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.06%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2023-37551

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-11-21 0.15% 0.06% -0.09%
2 2025-11-18 0.06% 0.15% +0.09%
3 2025-09-03 0.06%

Full EPSS history (10 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2023-37551

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.5 3.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:N)
Service keeps running; no real outage angle.
2.8 3.6 [email protected]
6.5 3.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:N)
Service keeps running; no real outage angle.
2.8 3.6 [email protected]

Weakness enumeration for CVE-2023-37551

Affected software / configurations for CVE-2023-37551

Vendor Product Version Raw CPE
codesys control_for_beaglebone_sl < 4.10.0.0 cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:*
codesys control_for_empc-a\/imx6_sl < 4.10.0.0 cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:*
codesys control_for_iot2000_sl < 4.10.0.0 cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*
codesys control_for_linux_sl < 4.10.0.0 cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:*
codesys control_for_pfc100_sl < 4.10.0.0 cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:*
codesys control_for_pfc200_sl < 4.10.0.0 cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:*
codesys control_for_plcnext_sl < 4.10.0.0 cpe:2.3:a:codesys:control_for_plcnext_sl:*:*:*:*:*:*:*:*
codesys control_for_raspberry_pi_sl < 4.10.0.0 cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*
codesys control_for_wago_touch_panels_600_sl < 4.10.0.0 cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:*
codesys control_rte_sl < 3.5.19.20 cpe:2.3:a:codesys:control_rte_sl:*:*:*:*:*:*:*:*
codesys control_rte_sl_\(for_beckhoff_cx\) < 3.5.19.20 cpe:2.3:a:codesys:control_rte_sl_\(for_beckhoff_cx\):*:*:*:*:*:*:*:*
codesys control_runtime_system_toolkit < 3.5.19.20 cpe:2.3:a:codesys:control_runtime_system_toolkit:*:*:*:*:*:*:*:*
codesys control_win_sl < 3.5.19.20 cpe:2.3:a:codesys:control_win_sl:*:*:*:*:*:*:*:*
codesys development_system < 3.5.19.20 cpe:2.3:a:codesys:development_system:*:*:*:*:*:*:*:*
codesys hmi < 3.5.19.20 cpe:2.3:a:codesys:hmi:*:*:*:*:*:*:*:*
codesys safety_sil2 < 3.5.19.20 cpe:2.3:a:codesys:safety_sil2:*:*:*:*:*:*:*:*

References for CVE-2023-37551

URL Tags
https://cert.vde.com/en/advisories/VDE-2023-019/ Third Party Advisory
cvelogic Threat Intelligence