CVE-2022-22516

HIGH

CODESYS Control RTE SL < 3.5.18.0 - Unauthenticated Memory Access via SysDrv3S Driver

Title source: llm
STIX 2.1

Description

The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space.

Scores

CVSS v3 7.8
EPSS 0.0025
EPSS Percentile 16.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (4)
codesys/control_rte_sl < 3.5.18.0
codesys/control_rte_sl_\(for_beckhoff_cx\) < 3.5.18.0
codesys/control_win_sl < 3.5.18.0
codesys/development_system < 3.5.18.0
Published Apr 07, 2022
Tracked Since Feb 18, 2026