CVE-2022-32137: CODESYS Runtime System prone to heap based buffer overflow
In multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause a heap-based buffer overflow, resulting in a denial-of-service condition or memory overwrite. User interaction is not required.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-32137 vulnerability?
CVE-2022-32137 is a vulnerability found in multiple CODESYS products that allows a low privileged remote attacker to cause a heap-based buffer overflow, resulting in a denial-of-service condition or memory overwrite.
Is user interaction required to exploit CVE-2022-32137?
No, user interaction is not required to exploit the CVE-2022-32137 vulnerability.
Which CODESYS products are affected by CVE-2022-32137?
The CODESYS PLCWinNT and Codesys Runtime Toolkit products are affected by CVE-2022-32137.
What is the severity rating of CVE-2022-32137?
CVE-2022-32137 has a high severity rating with a score of 8.8.
How can I fix the CVE-2022-32137 vulnerability?
To fix the CVE-2022-32137 vulnerability, users are advised to apply the latest security patches provided by CODESYS.