CVE-2022-22519: Special HTTP(s) Requests can cause a buffer-read causing a crash of the webserver and the runtime system.
Published Apr 7, 2022
·Updated
A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system.
Affected Software
18 affected components
CODESYS Control For Beaglebone Sl<4.5.0.0
CODESYS Control For Beckhoff Cx9020<4.5.0.0
CODESYS Control For Empc-a\/imx6 Sl<4.5.0.0
CODESYS Control For Iot2000 Sl<4.5.0.0
CODESYS Control For Linux Sl<4.5.0.0
CODESYS Control For Pfc100 Sl<4.5.0.0
CODESYS Control For Pfc200 Sl<4.5.0.0
CODESYS Control For Plcnext Sl<4.5.0.0
CODESYS Control For Raspberry Pi Sl<4.5.0.0
CODESYS Control For Wago Touch Panels 600 Sl<4.5.0.0
CODESYS Control Rte Sl<3.5.18.0
CODESYS Control Rte Sl \(for Beckhoff Cx\)<3.5.18.0
CODESYS Control Runtime System Toolkit<3.5.18.0
CODESYS Control Win Sl<3.5.18.0
CODESYS Development System<3.5.18.0
CODESYS Embedded Target Visu Toolkit<3.5.18.0
CODESYS Hmi Sl<3.5.18.0
CODESYS Remote Target Visu Toolkit<3.5.18.0
Event History
Apr 7, 2022
CVE Published
via MITRE·06:21 PM
Data Sourced
via MITRE·06:21 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-22519.
2
What is the severity level of CVE-2022-22519?
The severity level of CVE-2022-22519 is high with a score of 7.5.
3
Which software versions are affected by CVE-2022-22519?
CVE-2022-22519 affects various versions of CODESYS Control runtime system, including 4.5.0.0 and below.
4
What is the impact of CVE-2022-22519?
CVE-2022-22519 allows a remote, unauthenticated attacker to crash the webserver of the CODESYS Control runtime system by sending crafted HTTP or HTTPS requests causing a buffer over-read.
5
Is there a fix available for CVE-2022-22519?
Yes, it is recommended to update to a version of CODESYS Control runtime system beyond 4.5.0.0 to mitigate CVE-2022-22519.