PT-2022-21116 · 3S Smart Software Solutions · Codesys
Rigoblock
·
Published
2022-06-24
·
Updated
2022-07-01
·
CVE-2022-32143
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CODESYS products (affected versions not specified)
Description
The issue allows access to internal files in the working directory, such as firmware files of the PLC, through the file download and upload function. This is possible if no level 1 password is configured on the controller or if a remote attacker has previously successfully authenticated to the controller. A successful attack may lead to a denial of service, change of local files, or drain of confidential information. User interaction is not required.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Codesys