Vulnerability Description
A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Codesys | Control For Beaglebone Sl | < 4.5.0.0 |
| Codesys | Control For Beckhoff Cx9020 | < 4.5.0.0 |
| Codesys | Control For Empc-A\/Imx6 Sl | < 4.5.0.0 |
| Codesys | Control For Iot2000 Sl | < 4.5.0.0 |
| Codesys | Control For Linux Sl | < 4.5.0.0 |
| Codesys | Control For Pfc100 Sl | < 4.5.0.0 |
| Codesys | Control For Pfc200 Sl | < 4.5.0.0 |
| Codesys | Control For Plcnext Sl | < 4.5.0.0 |
| Codesys | Control For Raspberry Pi Sl | < 4.5.0.0 |
| Codesys | Control For Wago Touch Panels 600 Sl | < 4.5.0.0 |
| Codesys | Control Rte Sl | < 3.5.18.0 |
| Codesys | Control Rte Sl \(For Beckhoff Cx\) | < 3.5.18.0 |
| Codesys | Control Runtime System Toolkit | < 3.5.18.0 |
| Codesys | Control Win Sl | < 3.5.18.0 |
| Codesys | Development System | >= 3.0, < 3.5.18.0 |
| Codesys | Embedded Target Visu Toolkit | < 3.5.18.0 |
| Codesys | Hmi Sl | < 3.5.18.0 |
| Codesys | Remote Target Visu Toolkit | < 3.5.18.0 |
Related Weaknesses (CWE)
References
- https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17089&token=cc5041e24Vendor Advisory
- https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17089&token=cc5041e24Vendor Advisory
FAQ
What is CVE-2022-22515?
CVE-2022-22515 is a vulnerability with a CVSS score of 8.1 (HIGH). A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected ...
How severe is CVE-2022-22515?
CVE-2022-22515 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-22515?
Check the references section above for vendor advisories and patch information. Affected products include: Codesys Control For Beaglebone Sl, Codesys Control For Beckhoff Cx9020, Codesys Control For Empc-A\/Imx6 Sl, Codesys Control For Iot2000 Sl, Codesys Control For Linux Sl.