Multiple Vulnerabilities in CodeMeter Runtime bundled with DeviceXPlorer OPC Server

Security Advisory ID
SA-2025-001
Published
2025-03-01
Last Updated
2025-03-01

Vulnerability Details

The following vulnerabilities exist in CodeMeter Runtime (WIBU-SYSTEMS AG) bundled with DeviceXPlorer OPC Server. If exploited, a remote attacker may trigger a heap buffer overflow and execute arbitrary code.

CVE ID CVSS v3.1 Base Score Description References
CVE-2023-3935 9.8 (Critical) Heap buffer overflow in CodeMeter Runtime WIBU-SYSTEMS Security Advisories
CVE-2023-38545 9.8 (Critical) Heap buffer overflow in SOCKS5 proxy handling of the bundled libcurl WIBU-SYSTEMS Security Advisories

Affected Products

Product Affected Versions
DeviceXPlorer OPC Server Ver. 6.0.0 - 6.8.1
DeviceXPlorer OPC Server Ver. 7.0.0 - 7.3.3

Fixed Versions

Product Fixed Version
DeviceXPlorer OPC Server Ver. 6.8.2.1
DeviceXPlorer OPC Server Ver. 7.4.0.1

Contact

fa-support@takebishi.co.jp

Revision History

← Back to list