CVE-2022-22515 is a high-severity vulnerability affecting CODESYS Control runtime systems, specifically allowing authenticated remote attackers to read and modify configuration files. With a CVSS score of 8.1, it presents a low-complexity attack vector that can lead to significant compromise of confidentiality and integrity. While not currently listed on CISA's KEV catalog or having public exploit code in Metasploit or ExploitDB, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:* | ||
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_beckhoff_cx9020:*:*:*:*:*:*:*:* | ||
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:* | ||
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:* | ||
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022