CVE-2022-4046

In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.
References
Link Resource
https://cert.vde.com/en/advisories/VDE-2023-025/ Mitigation Third Party Advisory
https://cert.vde.com/en/advisories/VDE-2023-025/ Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_plcnext_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_sl_\(for_beckhoff_cx\):*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_runtime_system_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_win_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:hmi_sl:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:34

Type Values Removed Values Added
References () https://cert.vde.com/en/advisories/VDE-2023-025/ - Mitigation, Third Party Advisory () https://cert.vde.com/en/advisories/VDE-2023-025/ - Mitigation, Third Party Advisory

08 Aug 2023, 15:54

Type Values Removed Values Added
References (MISC) https://cert.vde.com/en/advisories/VDE-2023-025/ - (MISC) https://cert.vde.com/en/advisories/VDE-2023-025/ - Mitigation, Third Party Advisory
First Time Codesys control For Empc-a\/imx6 Sl
Codesys control Runtime System Toolkit
Codesys control For Wago Touch Panels 600 Sl
Codesys control Rte Sl
Codesys control For Pfc200 Sl
Codesys control For Pfc100 Sl
Codesys control Win Sl
Codesys control For Iot2000 Sl
Codesys control For Plcnext Sl
Codesys control For Linux Sl
Codesys control Rte Sl \(for Beckhoff Cx\)
Codesys control For Raspberry Pi Sl
Codesys control For Beaglebone Sl
Codesys
Codesys hmi Sl
CPE cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_sl_\(for_beckhoff_cx\):*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_plcnext_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_win_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_runtime_system_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:hmi_sl:*:*:*:*:*:*:*:*

03 Aug 2023, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-03 13:15

Updated : 2024-11-21 07:34


NVD link : CVE-2022-4046

Mitre link : CVE-2022-4046

CVE.ORG link : CVE-2022-4046


JSON object : View

Products Affected

codesys

  • control_runtime_system_toolkit
  • hmi_sl
  • control_for_iot2000_sl
  • control_rte_sl_\(for_beckhoff_cx\)
  • control_for_pfc200_sl
  • control_for_linux_sl
  • control_for_empc-a\/imx6_sl
  • control_for_raspberry_pi_sl
  • control_for_plcnext_sl
  • control_rte_sl
  • control_for_pfc100_sl
  • control_win_sl
  • control_for_wago_touch_panels_600_sl
  • control_for_beaglebone_sl
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer