CVE-2022-32137
24.06.2022, 08:15
In multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause a heap-based buffer overflow, resulting in a denial-of-service condition or memory overwrite. User interaction is not required.Enginsight
Vendor | Product | Version |
---|---|---|
codesys | plcwinnt | 2.0 ≤ 𝑥 < 2.4.7.57 |
codesys | runtime_toolkit | 2.0 ≤ 𝑥 < 2.4.7.57 |
𝑥
= Vulnerable software versions