// For flags

CVE-2022-22516

CODESYS driver SysDrv3S allows SYSTEM users on Microsoft Windows to read and write in restricted memory space.

Severity Score

7.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space.

El controlador SysDrv3S del sistema de tiempo de ejecuciĆ³n de CODESYS Control en Microsoft Windows permite a cualquier usuario del sistema leer y escribir en un espacio de memoria restringido

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-01-03 CVE Reserved
  • 2022-04-07 CVE Published
  • 2023-10-29 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Codesys
Search vendor "Codesys"
Control Rte Sl
Search vendor "Codesys" for product "Control Rte Sl"
< 3.5.18.0
Search vendor "Codesys" for product "Control Rte Sl" and version " < 3.5.18.0"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Codesys
Search vendor "Codesys"
Control Rte Sl \(for Beckhoff Cx\)
Search vendor "Codesys" for product "Control Rte Sl \(for Beckhoff Cx\)"
< 3.5.18.0
Search vendor "Codesys" for product "Control Rte Sl \(for Beckhoff Cx\)" and version " < 3.5.18.0"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Codesys
Search vendor "Codesys"
Control Win Sl
Search vendor "Codesys" for product "Control Win Sl"
< 3.5.18.0
Search vendor "Codesys" for product "Control Win Sl" and version " < 3.5.18.0"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Codesys
Search vendor "Codesys"
Development System
Search vendor "Codesys" for product "Development System"
< 3.5.18.0
Search vendor "Codesys" for product "Development System" and version " < 3.5.18.0"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe