← back
CVE-2022-47391highCWE-20

CODESYS: Multiple products prone to Improper Input Validation

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 1.9%
exploitation probability
1.9%top 23% of all CVEs
observed exploitation
nono source reports it
In short

CODESYS products don't properly check incoming data, allowing attackers to make the software crash by reading from invalid memory locations. This can take the system offline.

Technical detail

The vulnerability stems from improper input validation (CWE-20) in multiple CODESYS product versions, enabling unauthenticated remote attackers to trigger denial of service by forcing the application to read from invalid memory addresses. The attack requires network access to affected products with no prior authentication.

Summary generated and translated by AI from the official description.
In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from invalid addresses leading to a denial of service.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H