CVE-2022-30791 is an uncontrolled resource consumption vulnerability in the CmpBlkDrvTcp component of CODESYS V3, affecting multiple versions. This high-severity vulnerability (CVSS 7.5) allows an unauthenticated attacker to remotely block new TCP connections, leading to a denial of service for new connections, though existing connections remain unaffected. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not known to be actively exploited. Community discussion is minimal, with only one mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_beaglebone:*:*:*:*:*:*:*:* | ||
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_empc-a\/imx6:*:*:*:*:*:*:*:* | ||
< 4.6.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:* | ||
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:* | ||
< 4.5.0.0CPE matchmatch criteria | cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.