← back
CVE-2022-47379

CODESYS: Multiple products prone to out-of-bounds write

CVSS 8.8 HIGHEPSS 2.0%CWE-787
In short

A CODESYS software flaw allows a logged-in attacker to write data beyond memory boundaries, potentially crashing the system, corrupting data, or taking full control of the affected computer.

Technical detail

An out-of-bounds write vulnerability (CWE-787) in multiple CODESYS product versions permits authenticated remote attackers to corrupt heap or stack memory, leading to DoS, arbitrary data modification, or RCE depending on exploitation context and memory layout.

Summary generated and translated by AI from the official description.
An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →