← back
CVE-2022-4048

CODESYS V3 prone to Inadequate Encryption Stregth

CVSS 7.7 HIGHEPSS 0.1%CWE-326
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.7EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
15 May 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Inadequate Encryption Strength in CODESYS Development System V3 versions prior to V3.5.18.40 allows an unauthenticated local attacker to access and manipulate code of the encrypted boot application.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →