First published: Mon May 15 2023(Updated: )
Inadequate Encryption Strength in CODESYS Development System V3 versions prior to V3.5.18.40 allows an unauthenticated local attacker to access and manipulate code of the encrypted boot application.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
CODESYS Development System V3 | <3.5.18.40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4048 is a vulnerability in CODESYS Development System V3 versions prior to V3.5.18.40 that allows an unauthenticated local attacker to access and manipulate code of the encrypted boot application.
CVE-2022-4048 has a severity score of 7.7 (high).
An attacker can exploit CVE-2022-4048 by taking advantage of inadequate encryption strength in CODESYS Development System V3, allowing them to access and manipulate the code of the encrypted boot application.
Versions of CODESYS Development System V3 prior to V3.5.18.40 are affected by CVE-2022-4048.
To mitigate CVE-2022-4048, it is recommended to update CODESYS Development System V3 to version V3.5.18.40 or later.