First published: Wed Jun 15 2022(Updated: )
Multiple CODESYS Products are prone to a buffer over read. A low privileged remote attacker may craft a request with an invalid offset, which can cause an internal buffer over-read, resulting in a denial-of-service condition. User interaction is not required.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
CODESYS PLCWinNT | >=2.0<2.4.7.57 | |
Codesys Runtime Toolkit | >=2.0<2.4.7.57 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32141 is a vulnerability in multiple CODESYS Products that allows a low privileged remote attacker to cause a denial-of-service condition by crafting a request with an invalid offset, causing a buffer over-read.
The severity of CVE-2022-32141 is medium with a CVSS score of 6.5.
CODESYS PLCWinNT and Codesys Runtime Toolkit versions 2.0 to 2.4.7.57 are affected by CVE-2022-32141.
A low privileged remote attacker can craft a request with an invalid offset, causing an internal buffer over-read, leading to a denial-of-service condition.
No, user interaction is not required to exploit CVE-2022-32141.