CVE-2022-22518

A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymous access to components part of the applied security policy.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_beckhoff_cx9020:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_runtime_system_toolkit:*:*:*:*:*:*:*:*

History

18 Apr 2022, 13:24

Type Values Removed Values Added
CPE cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_runtime_system_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_beckhoff_cx9020:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:*
CWE CWE-286 CWE-276
CVSS v2 : unknown
v3 : unknown
v2 : 6.4
v3 : 6.5
First Time Codesys control Runtime System Toolkit
Codesys control For Empc-a\/imx6 Sl
Codesys control For Raspberry Pi Sl
Codesys control For Pfc100 Sl
Codesys
Codesys control For Beaglebone Sl
Codesys control For Pfc200 Sl
Codesys control For Linux Sl
Codesys control For Iot2000 Sl
Codesys control For Wago Touch Panels 600 Sl
Codesys control For Beckhoff Cx9020
References (MISC) https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17092&token=a556b1695843bb42084dc63d5bdf553ca02ea393&download= - (MISC) https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17092&token=a556b1695843bb42084dc63d5bdf553ca02ea393&download= - Vendor Advisory

07 Apr 2022, 19:50

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-07 19:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-22518

Mitre link : CVE-2022-22518

CVE.ORG link : CVE-2022-22518


JSON object : View

Products Affected

codesys

  • control_for_pfc200_sl
  • control_for_wago_touch_panels_600_sl
  • control_for_beaglebone_sl
  • control_for_pfc100_sl
  • control_runtime_system_toolkit
  • control_for_linux_sl
  • control_for_raspberry_pi_sl
  • control_for_empc-a\/imx6_sl
  • control_for_iot2000_sl
  • control_for_beckhoff_cx9020
CWE
CWE-276

Incorrect Default Permissions