First published: Wed Apr 06 2022(Updated: )
The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Codesys Control Rte Sl | <3.5.18.0 | |
Codesys Control Rte Sl \(for Beckhoff Cx\) | <3.5.18.0 | |
Codesys Control Win Sl | <3.5.18.0 | |
CODESYS Development System | <3.5.18.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22516 is a vulnerability in the SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows that allows any system user to read and write within restricted memory space.
CVE-2022-22516 affects the following software: Codesys Control Rte Sl, Codesys Control Rte Sl (for Beckhoff Cx), Codesys Control Win Sl, and CODESYS Development System (up to version 3.5.18.0).
The severity of CVE-2022-22516 is high with a CVSS score of 7.8.
To fix CVE-2022-22516, it is recommended to update the affected software to a version beyond 3.5.18.0.
You can find more information about CVE-2022-22516 at the following link: [https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17090&token=6cd08b169916366df31388d2e7ba58e7bce93508&download=](https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17090&token=6cd08b169916366df31388d2e7ba58e7bce93508&download=)