6.5

CVE-2022-22518

A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymous access to components part of the applied security policy.

Data is provided by the National Vulnerability Database (NVD)
CodesysControl For Beaglebone Sl Version >= 4.4.0.0 < 4.5.0.0
CodesysControl For Beckhoff Cx9020 Version >= 4.4.0.0 < 4.5.0.0
CodesysControl For Empc-a/imx6 Sl Version >= 4.4.0.0 < 4.5.0.0
CodesysControl For Iot2000 Sl Version >= 4.4.0.0 < 4.5.0.0
CodesysControl For Linux Sl Version >= 4.4.0.0 < 4.5.0.0
CodesysControl For Pfc100 Sl Version >= 4.4.0.0 < 4.5.0.0
CodesysControl For Pfc200 Sl Version >= 4.4.0.0 < 4.5.0.0
CodesysControl For Raspberry Pi Sl Version >= 4.4.0.0 < 4.5.0.0
CodesysControl For Wago Touch Panels 600 Sl Version >= 4.4.0.0 < 4.5.0.0
CodesysControl Runtime System Toolkit Version >= 3.5.17.0 < 3.5.18.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.16% 0.375
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
nvd@nist.gov 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
info@cert.vde.com 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.