CVE-2022-32139: CODESYS runtime system prone to denial of service due to out of bounds read
Published Jun 24, 2022
·Updated
In multiple CODESYS products, a low privileged remote attacker may craft a request, which cause an out-of-bounds read, resulting in a denial-of-service condition. User Interaction is not required.
Affected Software
2 affected components
CODESYS PLCWinNT>=2.0<2.4.7.57
CODESYS Runtime Toolkit>=2.0<2.4.7.57
Event History
Jun 24, 2022
CVE Published
via MITRE·07:46 AM
Data Sourced
via MITRE·07:46 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-32139.
2
What is the severity of CVE-2022-32139?
The severity of CVE-2022-32139 is medium, with a severity value of 6.5.
3
What is the affected software?
The affected software includes CODESYS PLCWinNT (version 2.0 to 2.4.7.57) and Codesys Runtime Toolkit (version 2.0 to 2.4.7.57).
4
What is the impact of CVE-2022-32139?
CVE-2022-32139 allows a low privileged remote attacker to cause a denial-of-service condition through an out-of-bounds read.
5
Is user interaction required to exploit CVE-2022-32139?
No, user interaction is not required to exploit CVE-2022-32139.