CVE-2022-47393: CODESYS: Multiple products prone to improperly restricted memory operations
An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple versions of multiple CODESYS products to force a denial-of-service situation.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2022-47393.
What is the severity level of CVE-2022-47393?
The severity level of CVE-2022-47393 is medium, with a severity value of 6.5.
Which products are affected by CVE-2022-47393?
Multiple versions of multiple CODESYS products are affected by CVE-2022-47393. The affected products include Codesys Control For Beaglebone Sl, Codesys Control For Empc-a/imx6 Sl, Codesys Control For Iot2000 Sl, Codesys Control For Linux Sl, Codesys Control For Pfc100 Sl, Codesys Control For Pfc200 Sl, Codesys Control For Plcnext Sl, Codesys Control For Raspberry Pi Sl, Codesys Control For Wago Touch Panels 600 Sl, Codesys Control Rte (for Beckhoff Cx) Sl, Codesys Control Rte (sl), Codesys Control Runtime System Toolkit, Codesys Control Win (sl), CODESYS Development System V3, Codesys Hmi (sl), Codesys Safety Sil2 Psp, and Codesys Safety Sil2 Runtime Toolkit.
What is the issue with CVE-2022-47393?
CVE-2022-47393 is an Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability, which can be exploited by an authenticated remote attacker to force a denial-of-service situation.
How can CVE-2022-47393 be fixed?
To fix CVE-2022-47393, it is recommended to update to a version that is not vulnerable. Please refer to the vendor's website for the latest patches and updates.