CVE-2022-4224: fallo de gravedad alta en CODESYS Control for BeagleBone SL
CODESYS: Exposure of Resource to Wrong Sphere in CODESYS V3
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.8epss 0.9%
probabilidad de explotación
0.9%top 42% de las CVE
explotación observada
noninguna fuente lo reporta
In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
CODESYS · Control for BeagleBone SLCODESYS · Control for emPC-A/iMX6 SLCODESYS · Control for IOT2000 SLCODESYS · Control for Linux SLCODESYS · Control for PFC100 SLCODESYS · Control for PFC200 SLCODESYS · Control for PLCnext SLCODESYS · Control for Raspberry Pi SLCODESYS · Control for WAGO Touch Panels 600 SLCODESYS · Control RTE (for Beckhoff CX) SLCODESYS · Control RTE (SL)CODESYS · Control Win (SL)CODESYS · Development System V3CODESYS · HMI (SL)CODESYS · Runtime ToolkitCODESYS · Safety SIL2 PSPCODESYS · Safety SIL2 Runtime ToolkitCVEs relacionadas — CODESYS Control for BeagleBone SL
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-41691HIGHCODESYS Control DoS via Unauthenticated NULL Pointer DereferenceEPSS 0.5%CVE-2026-79625HIGHImproper Synchronization in Monitoring in CODESYS Control RuntimeEPSS 0.2%CVE-2025-41659HIGHCODESYS Control PKI Exposure Enables Remote Certificate AccessEPSS 0.2%CVE-2025-41658MEDIUMCODESYS Toolkit Exposes Sensitive Files via Default PermissionsEPSS 0.1%