← back
CVE-2022-22515highCWE-668

A component of the CODESYS Control runtime system allows read and write access to configuration files

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.1epss 1.1%
exploitation probability
1.1%top 38% of all CVEs
observed exploitation
nono source reports it
A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N