A bug in the CODESYS V3 CmpUserMgr component fails to correctly apply a security policy.
CVE-2022-22518

6.5MEDIUM

What is CVE-2022-22518?

A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymous access to components part of the applied security policy.

Affected Version(s)

CODESYS Control for BeagleBone SL V4.5.0.0

CODESYS Control for Beckhoff CX9020 SL V4.5.0.0

CODESYS Control for emPC-A/iMX6 SL V4.5.0.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.