CVE-2022-22515

Severity
8.1HIGH
EPSS
0.2%
top 62.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 7
Latest updateApr 8

Description

A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages27 packages

🔴Vulnerability Details

2
GHSA
GHSA-v4p3-h3rx-q79h: A remote, unauthenticated attacker could utilize the control programmer of the CODESYS Control runtime system to use the vulnerability in order to rea2022-04-08
CVEList
A component of the CODESYS Control runtime system allows read and write access to configuration files2022-04-07
CVE-2022-22515 (HIGH CVSS 8.1) | cvebase.io