CVE-2022-4224: CODESYS: Exposure of Resource to Wrong Sphere in CODESYS V3
In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4224?
CVE-2022-4224 is a vulnerability in multiple products of CODESYS v3 in multiple versions, allowing a remote low privileged user to read and modify system files and OS resources or perform a denial-of-service (DoS) attack.
Which products are affected by CVE-2022-4224?
Multiple CODESYS v3 products, including Codesys Control For Beaglebone Sl, Codesys Control For Empc-a/imx6 Sl, Codesys Control For Iot2000 Sl, Codesys Control For Linux Sl, Codesys Control For Pfc100 Sl, Codesys Control For Pfc200 Sl, Codesys Control For Plcnext Sl, Codesys Control For Raspberry Pi Sl, and others, are affected by CVE-2022-4224.
What is the severity of CVE-2022-4224 vulnerability?
The severity of CVE-2022-4224 vulnerability is high, with a CVSS score of 8.8.
How can a remote attacker exploit CVE-2022-4224?
A remote low privileged user can exploit CVE-2022-4224 to read and modify system files and OS resources or perform a denial-of-service (DoS) attack.
Is there a solution or patch available for CVE-2022-4224?
Yes, it is recommended to update to the latest version of the affected CODESYS products to mitigate the vulnerability.