CVE-2022-22517 is an unauthenticated remote vulnerability affecting CODESYS products, allowing an attacker to disrupt communication channels. By guessing a valid channel ID and injecting packets, an attacker can force the closure of existing communication channels. This vulnerability has a CVSS score of 7.5 (High) due to its network attack vector, low attack complexity, and high availability impact, with no confidentiality or integrity impact. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), it is not listed in the KEV catalog, and community discussion is minimal, indicating low active exploitation or widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:* | ||
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_beckhoff_cx9020:*:*:*:*:*:*:*:* | ||
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:* | ||
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:* | ||
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022Vulnerabilities in the communication protocol of the PLC runtime
May 2, 2022