CVE-2022-4224

Severity
8.8HIGH
EPSS
1.1%
top 21.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 23

Description

In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages25 packages

NVDcodesys/development_system3.03.5.19.0
CVEListV5codesys/development_system_v33.0.0.03.5.19.0
NVDcodesys/hmi_sl3.03.5.19.0
NVDcodesys/control3.04.8.0.0
CVEListV5codesys/hmi_(sl)3.0.0.03.5.19.0

🔴Vulnerability Details

2
GHSA
GHSA-p8q2-j5x8-g597: In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files2023-03-23
CVEList
CODESYS: Exposure of Resource to Wrong Sphere in CODESYS V32023-03-23
CVE-2022-4224 (HIGH CVSS 8.8) | In multiple products of CODESYS v3 | cvebase.io