CVE-2022-22513 describes a null pointer dereference vulnerability in the CmpSettings component of CODESYS products. An authenticated remote attacker can exploit this flaw to cause a denial-of-service condition, resulting in a crash of the affected system. With a CVSS score of 6.5 (Medium), this vulnerability has a low attack complexity and requires authentication, but can lead to high availability impact. There is no public exploit code available, it is not listed in CISA's KEV catalog, and community discussion is minimal, suggesting it is not currently being actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:* | ||
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_beckhoff_cx9020:*:*:*:*:*:*:*:* | ||
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:* | ||
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:* | ||
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022