HIGH · 8.8

CVE-2022-4046

In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.

Vulnerability Description

In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CodesysControl For Beaglebone SlAll versions
CodesysControl For Empc-A\/Imx6 SlAll versions
CodesysControl For Iot2000 SlAll versions
CodesysControl For Linux SlAll versions
CodesysControl For Pfc100 SlAll versions
CodesysControl For Pfc200 SlAll versions
CodesysControl For Plcnext SlAll versions
CodesysControl For Raspberry Pi SlAll versions
CodesysControl For Wago Touch Panels 600 SlAll versions
CodesysControl Rte SlAll versions
CodesysControl Rte Sl \(For Beckhoff Cx\)All versions
CodesysControl Runtime System ToolkitAll versions
CodesysControl Win SlAll versions
CodesysHmi SlAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-4046?

CVE-2022-4046 is a vulnerability with a CVSS score of 8.8 (HIGH). In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.

How severe is CVE-2022-4046?

CVE-2022-4046 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-4046?

Check the references section above for vendor advisories and patch information. Affected products include: Codesys Control For Beaglebone Sl, Codesys Control For Empc-A\/Imx6 Sl, Codesys Control For Iot2000 Sl, Codesys Control For Linux Sl, Codesys Control For Pfc100 Sl.