Lucene search

K
nvd[email protected]NVD:CVE-2022-4046
HistoryAug 03, 2023 - 1:15 p.m.

CVE-2022-4046

2023-08-0313:15:09
CWE-119
web.nvd.nist.gov
codesys control
memory buffer
remote attacker
user privileges
device access

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.5%

In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.

Affected configurations

NVD
Node
codesyscontrol_for_beaglebone_sl
OR
codesyscontrol_for_empc-a\/imx6_sl
OR
codesyscontrol_for_iot2000_sl
OR
codesyscontrol_for_linux_sl
OR
codesyscontrol_for_pfc100_sl
OR
codesyscontrol_for_pfc200_sl
OR
codesyscontrol_for_plcnext_sl
OR
codesyscontrol_for_raspberry_pi_sl
OR
codesyscontrol_for_wago_touch_panels_600_sl
OR
codesyscontrol_rte_sl
OR
codesyscontrol_rte_sl_\(for_beckhoff_cx\)
OR
codesyscontrol_runtime_system_toolkit
OR
codesyscontrol_win_sl
OR
codesyshmi_sl

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.5%

Related for NVD:CVE-2022-4046