CODESYS: Multiple products prone to Improper Input Validation
CVE-2022-47391

7.5HIGH

What is CVE-2022-47391?

A vulnerability exists in multiple CODESYS products due to improper input validation, allowing unauthorized remote attackers to exploit this flaw. By reading from invalid memory addresses, attackers can potentially cause a denial of service, affecting the reliability and availability of the CODESYS systems. Users are encouraged to review their product versions and take appropriate measures to mitigate this risk.

Affected Version(s)

CODESYS Control for BeagleBone SL V0.0.0.0

CODESYS Control for emPC-A/iMX6 SL V0.0.0.0

CODESYS Control for IOT2000 SL V0.0.0.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vladimir Tokarev, Microsoft
.