CVE-2022-32138 is a high-severity vulnerability affecting multiple CODESYS products, including PLCWinNT and Runtime Toolkit, where a remote attacker can trigger an unexpected sign extension. This flaw can lead to a denial-of-service condition or a memory overwrite. With a CVSS score of 8.8 (High), it requires low privileges and network access, posing a significant risk of high impact to confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and it's not listed in CISA's KEV catalog, there has been some community discussion indicating awareness of the vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0, < 2.4.7.57CPE matchmatch criteria | cpe:2.3:a:codesys:plcwinnt:*:*:*:*:*:*:*:* | ||
>= 2.0, < 2.4.7.57CPE matchmatch criteria | cpe:2.3:a:codesys:runtime_toolkit:*:*:*:*:*:*:x86:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.