← back
CVE-2022-22517highCWE-334

Communication Components in multiple CODESYS products vulnerable to communication channel disruption

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 1.3%
exploitation probability
1.3%top 32% of all CVEs
observed exploitation
nono source reports it
In short

An attacker can disrupt communication between CODESYS products by guessing a channel ID and sending fake packets, forcing the connection to close. This breaks legitimate industrial control processes.

Technical detail

An unauthenticated remote attacker can disrupt CODESYS inter-product communication channels through packet injection by enumerating or guessing valid channel identifiers (CWE-334: Use of Insufficiently Random Values). The lack of authentication or strong channel validation allows an attacker to inject malicious packets that trigger closure of active communication channels, impacting availability.

Summary generated and translated by AI from the official description.
An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H