CVE-2022-4224

In multiple products of CODESYS v3 in multiple versions a remote low privileged usercould utilize this vulnerability to read and modify system files and OS resources or DoS the device.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CERTVDECNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
codesyscontrol_for_beaglebone_sl
3.0 ≤
𝑥
< 4.8.0.0
codesyscontrol_for_empc-a\/imx6_sl
3.0 ≤
𝑥
< 4.8.0.0
codesyscontrol_for_iot2000_sl
3.0 ≤
𝑥
< 4.8.0.0
codesyscontrol_for_linux_sl
3.0 ≤
𝑥
< 4.8.0.0
codesyscontrol_for_pfc100_sl
3.0 ≤
𝑥
< 4.8.0.0
codesyscontrol_for_pfc200_sl
3.0 ≤
𝑥
< 4.8.0.0
codesyscontrol_for_plcnext_sl
3.0 ≤
𝑥
< 4.8.0.0
codesyscontrol_for_raspberry_pi_sl
3.0 ≤
𝑥
< 4.8.0.0
codesyscontrol_for_wago_touch_panels_600_sl
3.0 ≤
𝑥
< 4.8.0.0
codesyscontrol_rte_sl
3.0 ≤
𝑥
< 3.5.19.0
codesyscontrol_rte_sl_\(for_beckhoff_cx\)
3.0 ≤
𝑥
< 3.5.19.0
codesyscontrol_win_sl
3.0 ≤
𝑥
< 3.5.19.0
codesysdevelopment_system
3.0 ≤
𝑥
< 3.5.19.0
codesyshmi_sl
3.0 ≤
𝑥
< 3.5.19.0
codesysruntime_toolkit
3.0 ≤
𝑥
< 3.5.19.0
codesyssafety_sil2
3.0 ≤
𝑥
< 3.5.19.0
𝑥
= Vulnerable software versions