CVE-2022-1965
24.06.2022, 08:15
Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required.Enginsight
Vendor | Product | Version |
---|---|---|
codesys | plcwinnt | 2.0 ≤ 𝑥 < 2.4.7.57 |
codesys | runtime_toolkit | 2.0 ≤ 𝑥 < 2.4.7.57 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration