← back
CVE-2022-22515

A component of the CODESYS Control runtime system allows read and write access to configuration files

CVSS 8.1 HIGHEPSS 1.1%CWE-668
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.1EPSS 1.1%KEV nãoPoC Patch
Lifecycle
Apr 07, 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →