CVE-2022-32143
CODESYS runtime system prone to directory acces
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the PLC. All requests are processed on the controller only if no level 1 password is configured on the controller or if remote attacker has previously successfully authenticated himself to the controller. A successful Attack may lead to a denial of service, change of local files, or drain of confidential Information. User interaction is not required
En Diversos productos CODESYS, la función de descarga y carga de archivos permite el acceso a archivos internos en el directorio de trabajo, por ejemplo, archivos de firmware del PLC. Todas las peticiones son procesadas en el controlador sólo si no presenta una contraseña de nivel 1 configurada en el controlador o si el atacante remoto ha sido autenticado previamente con éxito en el controlador. Un ataque con éxito puede conllevar a una denegación de servicio, la modificación de los archivos locales o un filtrado de información confidencial. No es requerida una interacción del usuario
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-31 CVE Reserved
- 2022-06-24 CVE Published
- 2024-09-06 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-552: Files or Directories Accessible to External Parties
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Codesys Search vendor "Codesys" | Plcwinnt Search vendor "Codesys" for product "Plcwinnt" | >= 2.0 < 2.4.7.57 Search vendor "Codesys" for product "Plcwinnt" and version " >= 2.0 < 2.4.7.57" | - |
Affected
| ||||||
Codesys Search vendor "Codesys" | Runtime Toolkit Search vendor "Codesys" for product "Runtime Toolkit" | >= 2.0 < 2.4.7.57 Search vendor "Codesys" for product "Runtime Toolkit" and version " >= 2.0 < 2.4.7.57" | x86 |
Affected
|