CVE-2022-1965 describes an improper error handling vulnerability in CODESYS PLCWinNT and Runtime Toolkit products. A low-privileged remote attacker can craft a malicious request, leading to the deletion of arbitrary files due to the flawed error handling. This vulnerability has a CVSS score of 8.1 (High), indicating a significant impact with high integrity and availability loss, requiring no user interaction. There is currently no evidence of active exploitation, and public exploit code (Metasploit, Nuclei, ExploitDB) is unavailable. Community discussion is minimal, with only one mention, and there is no media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0, < 2.4.7.57CPE matchmatch criteria | cpe:2.3:a:codesys:plcwinnt:*:*:*:*:*:*:*:* | ||
>= 2.0, < 2.4.7.57CPE matchmatch criteria | cpe:2.3:a:codesys:runtime_toolkit:*:*:*:*:*:*:x86:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.