CVE-2022-1965

HIGH

CODESYS PLCWinNT and Runtime Toolkit 2.0-2.4.7.56 - Unauthenticated Arbitrary File Deletion via Improper Error Handling

Title source: llm
STIX 2.1

Description

Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required.

References (1)

Core 1

Scores

CVSS v3 8.1
EPSS 0.0090
EPSS Percentile 54.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-755
Status published
Products (2)
codesys/plcwinnt 2.0 - 2.4.7.57
codesys/runtime_toolkit 2.0 - 2.4.7.57
Published Jun 24, 2022
Tracked Since Feb 18, 2026