CVE-2022-22515

A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_beckhoff_cx9020:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_plcnext_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_sl_\(for_beckhoff_cx\):*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_runtime_system_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_win_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:development_system:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:embedded_target_visu_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:hmi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:remote_target_visu_toolkit:*:*:*:*:*:*:*:*

History

27 Apr 2022, 06:15

Type Values Removed Values Added
Summary A remote, unauthenticated attacker could utilize the control programmer of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products. A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.

18 Apr 2022, 10:39

Type Values Removed Values Added
References (MISC) https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17089&token=cc5041e24fc744a397a6f6e3b78200a40e6fcd53&download= - (MISC) https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17089&token=cc5041e24fc744a397a6f6e3b78200a40e6fcd53&download= - Vendor Advisory
First Time Codesys hmi Sl
Codesys control For Empc-a\/imx6 Sl
Codesys control Rte Sl
Codesys control For Beaglebone Sl
Codesys embedded Target Visu Toolkit
Codesys control For Linux Sl
Codesys control Rte Sl \(for Beckhoff Cx\)
Codesys control For Beckhoff Cx9020
Codesys remote Target Visu Toolkit
Codesys control Runtime System Toolkit
Codesys control For Raspberry Pi Sl
Codesys control For Pfc100 Sl
Codesys
Codesys control For Pfc200 Sl
Codesys control Win Sl
Codesys development System
Codesys control For Iot2000 Sl
Codesys control For Plcnext Sl
Codesys control For Wago Touch Panels 600 Sl
CVSS v2 : unknown
v3 : unknown
v2 : 4.9
v3 : 8.1
CPE cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:remote_target_visu_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_sl_\(for_beckhoff_cx\):*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_plcnext_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_win_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_runtime_system_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:hmi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_beckhoff_cx9020:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:embedded_target_visu_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:development_system:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_sl:*:*:*:*:*:*:*:*

07 Apr 2022, 19:50

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-07 19:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-22515

Mitre link : CVE-2022-22515

CVE.ORG link : CVE-2022-22515


JSON object : View

Products Affected

codesys

  • control_for_iot2000_sl
  • control_for_wago_touch_panels_600_sl
  • remote_target_visu_toolkit
  • development_system
  • control_for_pfc200_sl
  • control_for_beaglebone_sl
  • control_win_sl
  • control_rte_sl_\(for_beckhoff_cx\)
  • control_runtime_system_toolkit
  • hmi_sl
  • control_for_beckhoff_cx9020
  • control_rte_sl
  • control_for_empc-a\/imx6_sl
  • control_for_raspberry_pi_sl
  • control_for_plcnext_sl
  • embedded_target_visu_toolkit
  • control_for_pfc100_sl
  • control_for_linux_sl
CWE
CWE-668

Exposure of Resource to Wrong Sphere