CVE-2022-1965

HIGH

CODESYS - Info Disclosure

Title source: llm

Description

Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required.

Scores

CVSS v3 8.1
EPSS 0.0079
EPSS Percentile 73.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Classification

CWE
CWE-755
Status published

Affected Products (2)

codesys/plcwinnt < 2.4.7.57
codesys/runtime_toolkit < 2.4.7.57

Timeline

Published Jun 24, 2022
Tracked Since Feb 18, 2026