CODESYS: Exposure of Resource to Wrong Sphere in CODESYS V3
Vulnerability Description
In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-4224
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Franklin Zhao from ELEX FEIGONG RESEARCH INSTITUTE of Elex CyberSecurity
- Reid Wightman of Dragos
More from CODESYS
View All →Affected Vendor
CODESYS
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.