CVE-2023-3935: Phoenixcontact Activation Wizard
Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.
A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
Affected products
- Phoenixcontact Activation Wizard: up to and including 1.6
- Phoenixcontact E-Mobility Charging Suite: up to and including 1.7.0
- Phoenixcontact Fl Network Manager: up to and including 7.0
- Phoenixcontact Iol-Conf: up to and including 1.7.0
- Phoenixcontact Module Type Package Designer: before 1.2.0 (fixed in 1.2.0); version 1.2.0 only
- Phoenixcontact Plcnext Engineer: up to and including 2023.6
- Trumpf Oseon: from 1.0.0, up to and including 3.0.22
- Trumpf Programmingtube: from 1.0.1, up to and including 4.6.3
- Trumpf Teczonebend: from 18.02.r8, up to and including 23.06.01
- Trumpf Tops Unfold: version 05.03.00.00 only
- Trumpf Topscalculation: from 14.00, up to and including 22.00.00
- Trumpf Trumpflicenseexpert: from 1.5.2, up to and including 1.11.1
- Trumpf Trutops: from 08.00, up to and including 12.01.00.00
- Trumpf Trutops Cell Classic: up to and including 09.09.02
- Trumpf Trutops Cell SW48: from 01.00, up to and including 02.26.0
- Trumpf Trutops Mark 3d: from 01.00, up to and including 06.01
- Trumpf Trutopsboost: from 06.00.23.00, up to and including 16.0.22
- Trumpf Trutopsfab: from 15.00.23.00, up to and including 22.8.25
- Trumpf Trutopsfab Storage Smallstore: from 14.06.20, up to and including 20.04.20.00
- Trumpf Trutopsprint: from 00.06.00, up to and including 01.00
- Trumpf Trutopsprintmultilaserassistant: from 01.02
- Trumpf Trutopsweld: from 7.0.198.241, up to and including 9.0.28148.1
- Trumpf Tubedesign: from 08.00, up to and including 14.06.150
- Wibu Codemeter Runtime: before 7.60c (fixed in 7.60c)
Published 2023-09-13. Last modified 2026-06-17.