Vulnerability CVE-2022-22513


Published: 2022-04-07

Description:
An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.

Type:

CWE-476

(NULL Pointer Dereference)

CVSS2 => (AV:N/AC:M/Au:S/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
3.5/10
2.9/10
6.8/10
Exploit range
Attack complexity
Authentication
Remote
Medium
Single time
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Codesys -> Edge gateway 
Codesys -> Control for beaglebone sl 
Codesys -> Embedded target visu toolkit 
Codesys -> Control for beckhoff cx9020 
Codesys -> Gateway 
Codesys -> Control for empc-a\/imx6 sl 
Codesys -> Hmi sl 
Codesys -> Control for iot2000 sl 
Codesys -> Remote target visu toolkit 
Codesys -> Control for linux sl 
Codesys -> Control for pfc100 sl 
Codesys -> Control for pfc200 sl 
Codesys -> Control for plcnext sl 
Codesys -> Control for raspberry pi sl 
Codesys -> Control for wago touch panels 600 sl 
Codesys -> Control rte sl 
Codesys -> Control rte sl \(for beckhoff cx\) 
Codesys -> Control runtime system toolkit 
Codesys -> Control win sl 
Codesys -> Development system 

 References:
https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17093&token=15cd8424832ea10dcd4873a409a09a539ee381ca&download
=

Copyright 2022, cxsecurity.com

 

Back to Top