CVE-2022-22508

Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block consecutive logins of a specific type.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_plcnext_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_\(for_beckhoff_cx\)_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_\(sl\):*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_runtime_system_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_win_\(sl\):*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:hmi_\(sl\):*:*:*:*:*:*:*:*

History

26 May 2023, 17:09

Type Values Removed Values Added
First Time Codesys control Win \(sl\)
Codesys hmi \(sl\)
Codesys control For Linux Sl
Codesys control For Pfc100 Sl
Codesys control Rte \(sl\)
Codesys control For Empc-a\/imx6 Sl
Codesys
Codesys control For Pfc200 Sl
Codesys control For Plcnext Sl
Codesys control For Wago Touch Panels 600 Sl
Codesys control For Raspberry Pi Sl
Codesys control For Beaglebone Sl
Codesys control For Iot2000 Sl
Codesys control Runtime System Toolkit
Codesys control Rte \(for Beckhoff Cx\) Sl
CPE cpe:2.3:a:codesys:control_win_\(sl\):*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_\(sl\):*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_\(for_beckhoff_cx\)_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_plcnext_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_runtime_system_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:hmi_\(sl\):*:*:*:*:*:*:*:*
References (MISC) https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17351&token=a7c02b2825fea2bcaf80c1a8e62097d72ec90f1a&download= - (MISC) https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17351&token=a7c02b2825fea2bcaf80c1a8e62097d72ec90f1a&download= - Vendor Advisory

Information

Published : 2023-05-15 10:15

Updated : 2024-02-28 20:13


NVD link : CVE-2022-22508

Mitre link : CVE-2022-22508

CVE.ORG link : CVE-2022-22508


JSON object : View

Products Affected

codesys

  • control_for_empc-a\/imx6_sl
  • control_for_iot2000_sl
  • control_for_wago_touch_panels_600_sl
  • control_for_raspberry_pi_sl
  • control_rte_\(for_beckhoff_cx\)_sl
  • hmi_\(sl\)
  • control_runtime_system_toolkit
  • control_for_beaglebone_sl
  • control_for_plcnext_sl
  • control_for_pfc100_sl
  • control_for_linux_sl
  • control_for_pfc200_sl
  • control_win_\(sl\)
  • control_rte_\(sl\)
CWE
CWE-20

Improper Input Validation