CVE-2022-47381: CODESYS: Multiple products prone to stack based out-of-bounds write
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-47381 vulnerability?
The severity of CVE-2022-47381 vulnerability is high with a severity value of 8.8.
How does CVE-2022-47381 vulnerability affect CODESYS products?
CVE-2022-47381 vulnerability affects multiple CODESYS products in multiple versions.
What is the impact of CVE-2022-47381 vulnerability?
CVE-2022-47381 vulnerability can lead to a denial-of-service condition, memory overwriting, or remote code execution.
Which products are affected by CVE-2022-47381 vulnerability?
CVE-2022-47381 vulnerability affects multiple versions of CODESYS Control For Beaglebone Sl, CODESYS Control For Empc-a/imx6 Sl, CODESYS Control For Iot2000 Sl, CODESYS Control For Linux Sl, CODESYS Control For Pfc100 Sl, CODESYS Control For Pfc200 Sl, CODESYS Control For Plcnext Sl, CODESYS Control For Raspberry Pi Sl, CODESYS Control For Wago Touch Panels 600 Sl, Codesys Control Rte (for Beckhoff Cx) Sl, Codesys Control Rte (sl), Codesys Control Runtime System Toolkit, Codesys Control Win (sl), CODESYS Development System V3, Codesys Hmi (sl), Codesys Safety Sil2 Psp, and Codesys Safety Sil2 Runtime Toolkit.
How can I fix CVE-2022-47381 vulnerability?
To fix CVE-2022-47381 vulnerability, it is recommended to update to a version higher than 3.5.19.0 for the affected CODESYS products.