8.1

CVE-2022-22515

A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.

Data is provided by the National Vulnerability Database (NVD)
CodesysControl For Beaglebone Sl Version < 4.5.0.0
CodesysControl For Beckhoff Cx9020 Version < 4.5.0.0
CodesysControl For Empc-a/imx6 Sl Version < 4.5.0.0
CodesysControl For Iot2000 Sl Version < 4.5.0.0
CodesysControl For Linux Sl Version < 4.5.0.0
CodesysControl For Pfc100 Sl Version < 4.5.0.0
CodesysControl For Pfc200 Sl Version < 4.5.0.0
CodesysControl For Plcnext Sl Version < 4.5.0.0
CodesysControl For Raspberry Pi Sl Version < 4.5.0.0
CodesysControl Rte Sl Version < 3.5.18.0
CodesysControl Runtime System Toolkit Version < 3.5.18.0
CodesysControl Win Sl Version < 3.5.18.0
CodesysDevelopment System Version >= 3.0 < 3.5.18.0
CodesysEmbedded Target Visu Toolkit Version < 3.5.18.0
CodesysHmi Sl Version < 3.5.18.0
CodesysRemote Target Visu Toolkit Version < 3.5.18.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.268
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.9 6.8 4.9
AV:N/AC:M/Au:S/C:P/I:P/A:N
nvd@nist.gov 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
info@cert.vde.com 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CWE-668 Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.