← back
CVE-2022-22518

A bug in the CODESYS V3 CmpUserMgr component fails to correctly apply a security policy.

CVSS 6.5 MEDIUMEPSS 0.6%CWE-276
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 0.6%KEV nãoPoC Patch
Lifecycle
07 Apr 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymous access to components part of the applied security policy.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →