CVE-2022-4046
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
03/08/2023
Last modified:
08/08/2023
Description
In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:* | ||
| cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:* | ||
| cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:* | ||
| cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:* | ||
| cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:* | ||
| cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:* | ||
| cpe:2.3:a:codesys:control_for_plcnext_sl:*:*:*:*:*:*:*:* | ||
| cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:* | ||
| cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:* | ||
| cpe:2.3:a:codesys:control_rte_sl:*:*:*:*:*:*:*:* | ||
| cpe:2.3:a:codesys:control_rte_sl_\(for_beckhoff_cx\):*:*:*:*:*:*:*:* | ||
| cpe:2.3:a:codesys:control_runtime_system_toolkit:*:*:*:*:*:*:*:* | ||
| cpe:2.3:a:codesys:control_win_sl:*:*:*:*:*:*:*:* | ||
| cpe:2.3:a:codesys:hmi_sl:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



