CVE-2022-22514 is a high-severity vulnerability affecting CODESYS products, allowing an authenticated, remote attacker to trigger a dereferenced pointer in the CmpTraceMgr component. This can lead to local memory overwriting and system crashes, though attackers cannot control the written values or read internal data. The vulnerability has a CVSS score of 7.1 (High) due to its network attack vector and low attack complexity, resulting in a high impact on availability and a low impact on integrity. While there is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has received minimal community discussion, with one mention on Mastodon.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:* | ||
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_beckhoff_cx9020:*:*:*:*:*:*:*:* | ||
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:* | ||
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:* | ||
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022