8.8

CVE-2022-4224

In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CodesysControl For Beaglebone Sl Version >= 3.0 < 4.8.0.0
CodesysControl For Empc-a/imx6 Sl Version >= 3.0 < 4.8.0.0
CodesysControl For Iot2000 Sl Version >= 3.0 < 4.8.0.0
CodesysControl For Linux Sl Version >= 3.0 < 4.8.0.0
CodesysControl For Pfc100 Sl Version >= 3.0 < 4.8.0.0
CodesysControl For Pfc200 Sl Version >= 3.0 < 4.8.0.0
CodesysControl For Plcnext Sl Version >= 3.0 < 4.8.0.0
CodesysControl For Raspberry Pi Sl Version >= 3.0 < 4.8.0.0
CodesysControl For Wago Touch Panels 600 Sl Version >= 3.0 < 4.8.0.0
CodesysControl Rte Sl Version >= 3.0 < 3.5.19.0
CodesysControl Rte Sl (for Beckhoff Cx) Version >= 3.0 < 3.5.19.0
CodesysControl Win Sl Version >= 3.0 < 3.5.19.0
CodesysDevelopment System Version >= 3.0 < 3.5.19.0
CodesysHmi Sl Version >= 3.0 < 3.5.19.0
CodesysRuntime Toolkit Version >= 3.0 < 3.5.19.0
CodesysSafety Sil2 Version >= 3.0 < 3.5.19.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.668
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
info@cert.vde.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-1188 Initialization of a Resource with an Insecure Default

The product initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.