CVE Vulnerabilities

CVE-2022-1965

Improper Handling of Exceptional Conditions

Published: Jun 24, 2022 | Modified: Oct 26, 2022
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

Name Vendor Start Version End Version
Plcwinnt Codesys 2.0 (including) 2.4.7.57 (excluding)
Runtime_toolkit Codesys 2.0 (including) 2.4.7.57 (excluding)

References