CVE-2022-4224

In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
codesyscontrol_for_beaglebone_sl
3.0 ≤
𝑥
< 4.8.0.0
codesyscontrol_for_empc-a\/imx6_sl
3.0 ≤
𝑥
< 4.8.0.0
codesyscontrol_for_iot2000_sl
3.0 ≤
𝑥
< 4.8.0.0
codesyscontrol_for_linux_sl
3.0 ≤
𝑥
< 4.8.0.0
codesyscontrol_for_pfc100_sl
3.0 ≤
𝑥
< 4.8.0.0
codesyscontrol_for_pfc200_sl
3.0 ≤
𝑥
< 4.8.0.0
codesyscontrol_for_plcnext_sl
3.0 ≤
𝑥
< 4.8.0.0
codesyscontrol_for_raspberry_pi_sl
3.0 ≤
𝑥
< 4.8.0.0
codesyscontrol_for_wago_touch_panels_600_sl
3.0 ≤
𝑥
< 4.8.0.0
codesyscontrol_rte_sl
3.0 ≤
𝑥
< 3.5.19.0
codesyscontrol_rte_sl_\(for_beckhoff_cx\)
3.0 ≤
𝑥
< 3.5.19.0
codesyscontrol_win_sl
3.0 ≤
𝑥
< 3.5.19.0
codesysdevelopment_system
3.0 ≤
𝑥
< 3.5.19.0
codesyshmi_sl
3.0 ≤
𝑥
< 3.5.19.0
codesysruntime_toolkit
3.0 ≤
𝑥
< 3.5.19.0
codesyssafety_sil2
3.0 ≤
𝑥
< 3.5.19.0
𝑥
= Vulnerable software versions