HIGH · 8.1

CVE-2022-22515

A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected ...

Vulnerability Description

A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.

CVSS Score

8.1

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
CodesysControl For Beaglebone Sl< 4.5.0.0
CodesysControl For Beckhoff Cx9020< 4.5.0.0
CodesysControl For Empc-A\/Imx6 Sl< 4.5.0.0
CodesysControl For Iot2000 Sl< 4.5.0.0
CodesysControl For Linux Sl< 4.5.0.0
CodesysControl For Pfc100 Sl< 4.5.0.0
CodesysControl For Pfc200 Sl< 4.5.0.0
CodesysControl For Plcnext Sl< 4.5.0.0
CodesysControl For Raspberry Pi Sl< 4.5.0.0
CodesysControl For Wago Touch Panels 600 Sl< 4.5.0.0
CodesysControl Rte Sl< 3.5.18.0
CodesysControl Rte Sl \(For Beckhoff Cx\)< 3.5.18.0
CodesysControl Runtime System Toolkit< 3.5.18.0
CodesysControl Win Sl< 3.5.18.0
CodesysDevelopment System>= 3.0, < 3.5.18.0
CodesysEmbedded Target Visu Toolkit< 3.5.18.0
CodesysHmi Sl< 3.5.18.0
CodesysRemote Target Visu Toolkit< 3.5.18.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-22515?

CVE-2022-22515 is a vulnerability with a CVSS score of 8.1 (HIGH). A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected ...

How severe is CVE-2022-22515?

CVE-2022-22515 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-22515?

Check the references section above for vendor advisories and patch information. Affected products include: Codesys Control For Beaglebone Sl, Codesys Control For Beckhoff Cx9020, Codesys Control For Empc-A\/Imx6 Sl, Codesys Control For Iot2000 Sl, Codesys Control For Linux Sl.