CVE-2022-32142: CODESYS runtime system prone to denial of service due to use of out of range pointer
Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset, which can cause an out-of-bounds read or write access, resulting in denial-of-service condition or local memory overwrite, which can lead to a change of local files. User interaction is not required.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-32142?
CVE-2022-32142 is a vulnerability in multiple CODESYS Products that allows for out-of-bounds read or write access, leading to denial-of-service or local memory overwrite.
How can a low privileged remote attacker exploit CVE-2022-32142?
A low privileged remote attacker can exploit CVE-2022-32142 by crafting a request with an invalid offset, causing an out-of-bounds read or write access.
What is the severity of CVE-2022-32142?
CVE-2022-32142 has a severity rating of 8.1 (high).
Which CODESYS Products are affected by CVE-2022-32142?
CODESYS PLCWinNT and Codesys Runtime Toolkit versions 2.0 to 2.4.7.57 are affected by CVE-2022-32142.
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-32142?
The CWE ID for CVE-2022-32142 is CWE-823.