PT-2022-21116 · 3S Smart Software Solutions · Codesys

Rigoblock

·

Published

2022-06-24

·

Updated

2022-07-01

·

CVE-2022-32143

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CODESYS products (affected versions not specified)
Description The issue allows access to internal files in the working directory, such as firmware files of the PLC, through the file download and upload function. This is possible if no level 1 password is configured on the controller or if a remote attacker has previously successfully authenticated to the controller. A successful attack may lead to a denial of service, change of local files, or drain of confidential information. User interaction is not required.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-32143

Affected Products

Codesys