CVE-2022-32142
CODESYS runtime system prone to denial of service due to use of out of range pointer
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset, which can cause an out-of-bounds read or write access, resulting in denial-of-service condition or local memory overwrite, which can lead to a change of local files. User interaction is not required.
Diversos productos CODESYS son propensos a un acceso de lectura o escritura fuera de límites. Un atacante remoto poco privilegiado puede diseñar una petición con un desplazamiento no válido, lo que puede causar un acceso de lectura o escritura fuera de límites, resultando en una condición de denegación de servicio o a una sobreescritura de la memoria local, lo que puede conllevar a un cambio de los archivos locales. No es requerida una interacción del usuario
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-31 CVE Reserved
- 2022-06-24 CVE Published
- 2024-09-17 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-823: Use of Out-of-range Pointer Offset
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Codesys Search vendor "Codesys" | Plcwinnt Search vendor "Codesys" for product "Plcwinnt" | >= 2.0 < 2.4.7.57 Search vendor "Codesys" for product "Plcwinnt" and version " >= 2.0 < 2.4.7.57" | - |
Affected
| ||||||
Codesys Search vendor "Codesys" | Runtime Toolkit Search vendor "Codesys" for product "Runtime Toolkit" | >= 2.0 < 2.4.7.57 Search vendor "Codesys" for product "Runtime Toolkit" and version " >= 2.0 < 2.4.7.57" | x86 |
Affected
|