HIGH🇵🇱 Wersja polska

CVE-2022-32137

CVSS 8.8v3.1pub. 2022-06-24upd. 2024-11-21

In multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause a heap-based buffer overflow, resulting in a denial-of-service condition or memory overwrite. User interaction is not required.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Codesys Plcwinnt

    APP
    Codesys
    2.0 – 2.4.7.57 (excl.)
  • Codesys Runtime Toolkit

    APP
    Codesys
    2.0 – 2.4.7.57 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2022-31806CRITICAL9.8PL ✓same product

CODESYS V2 PLCWinNT/Runtime Toolkit — brak domyślnego hasła na kontrolerze

CVE-2025-41738HIGH7.5same product

An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to...

CVE-2023-6357HIGH8.8same product

A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via fil...

CVE-2022-4224HIGH8.8same product

In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulner...

CVE-2022-1965HIGH8.1same product

Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a ...