6.5
CVE-2022-22518
- EPSS 0.16%
- Published 07.04.2022 19:15:08
- Last modified 21.11.2024 06:46:56
- Source info@cert.vde.com
- Teams watchlist Login
- Open Login
A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymous access to components part of the applied security policy.
Data is provided by the National Vulnerability Database (NVD)
Codesys ≫ Control For Beaglebone Sl Version >= 4.4.0.0 < 4.5.0.0
Codesys ≫ Control For Beckhoff Cx9020 Version >= 4.4.0.0 < 4.5.0.0
Codesys ≫ Control For Empc-a/imx6 Sl Version >= 4.4.0.0 < 4.5.0.0
Codesys ≫ Control For Iot2000 Sl Version >= 4.4.0.0 < 4.5.0.0
Codesys ≫ Control For Linux Sl Version >= 4.4.0.0 < 4.5.0.0
Codesys ≫ Control For Pfc100 Sl Version >= 4.4.0.0 < 4.5.0.0
Codesys ≫ Control For Pfc200 Sl Version >= 4.4.0.0 < 4.5.0.0
Codesys ≫ Control For Raspberry Pi Sl Version >= 4.4.0.0 < 4.5.0.0
Codesys ≫ Control For Wago Touch Panels 600 Sl Version >= 4.4.0.0 < 4.5.0.0
Codesys ≫ Control Runtime System Toolkit Version >= 3.5.17.0 < 3.5.18.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.16% | 0.375 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:P/I:P/A:N
|
nvd@nist.gov | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
info@cert.vde.com | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.