CVE-2022-22517: high-severity vulnerability in CODESYS Control for BeagleBone SL
Communication Components in multiple CODESYS products vulnerable to communication channel disruption
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
An attacker can disrupt communication between CODESYS products by guessing a channel ID and sending fake packets, forcing the connection to close. This breaks legitimate industrial control processes.
An unauthenticated remote attacker can disrupt CODESYS inter-product communication channels through packet injection by enumerating or guessing valid channel identifiers (CWE-334: Use of Insufficiently Random Values). The lack of authentication or strong channel validation allows an attacker to inject malicious packets that trigger closure of active communication channels, impacting availability.
In the same product, most dangerous first.