Vulnerability Description
In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Codesys | Control For Beaglebone | < 4.5.0.0 |
| Codesys | Control For Empc-A\/Imx6 | < 4.5.0.0 |
| Codesys | Control For Iot2000 Sl | < 4.6.0.0 |
| Codesys | Control For Linux Sl | < 4.5.0.0 |
| Codesys | Control For Pfc100 Sl | < 4.5.0.0 |
| Codesys | Control For Pfc200 Sl | < 4.5.0.0 |
| Codesys | Control For Plcnext | < 4.6.0.0 |
| Codesys | Control For Raspberry Pi Sl | < 4.5.0.0 |
| Codesys | Control For Wago Touch Panels 600 | < 4.5.0.0 |
| Codesys | Control Rte Sl | < 3.5.18.20 |
| Codesys | Control Rte Sl \(For Beckhoff Cx\) | < 3.5.18.20 |
| Codesys | Control Runtime System Toolkit | < 3.5.18.20 |
| Codesys | Control Win | < 3.5.18.20 |
| Codesys | Development System | < 3.5.18.20 |
| Codesys | Edge Gateway | < 3.5.18.20 |
| Codesys | Embedded Target Visu Toolkit | < 3.5.18.20 |
| Codesys | Gateway | < 3.5.18.20 |
| Codesys | Hmi | < 3.5.18.20 |
| Codesys | Remote Target Visu Toolkit | < 3.5.18.20 |
Related Weaknesses (CWE)
References
- https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17128&token=bee4d8a57Vendor Advisory
- https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17128&token=bee4d8a57Vendor Advisory
FAQ
What is CVE-2022-30792?
CVE-2022-30792 is a vulnerability with a CVSS score of 7.5 (HIGH). In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are no...
How severe is CVE-2022-30792?
CVE-2022-30792 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-30792?
Check the references section above for vendor advisories and patch information. Affected products include: Codesys Control For Beaglebone, Codesys Control For Empc-A\/Imx6, Codesys Control For Iot2000 Sl, Codesys Control For Linux Sl, Codesys Control For Pfc100 Sl.