CVE-2022-32141: CODESYS runtime system prone to denial of service due to buffer over read
Multiple CODESYS Products are prone to a buffer over read. A low privileged remote attacker may craft a request with an invalid offset, which can cause an internal buffer over-read, resulting in a denial-of-service condition. User interaction is not required.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-32141?
CVE-2022-32141 is a vulnerability in multiple CODESYS Products that allows a low privileged remote attacker to cause a denial-of-service condition by crafting a request with an invalid offset, causing a buffer over-read.
What is the severity of CVE-2022-32141?
The severity of CVE-2022-32141 is medium with a CVSS score of 6.5.
Which CODESYS Products are affected by CVE-2022-32141?
CODESYS PLCWinNT and Codesys Runtime Toolkit versions 2.0 to 2.4.7.57 are affected by CVE-2022-32141.
How does CVE-2022-32141 work?
A low privileged remote attacker can craft a request with an invalid offset, causing an internal buffer over-read, leading to a denial-of-service condition.
Is user interaction required to exploit CVE-2022-32141?
No, user interaction is not required to exploit CVE-2022-32141.