CVE-2022-22518

MEDIUM

CODESYS Control Runtime System Toolkit 3.5.17.0 - Incorrect Default Permissions in CmpUserMgr

Title source: llm
STIX 2.1

Description

A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymous access to components part of the applied security policy.

Scores

CVSS v3 6.5
EPSS 0.0057
EPSS Percentile 42.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-276
Status published
Products (10)
codesys/control_for_beaglebone_sl 4.4.0.0 - 4.5.0.0
codesys/control_for_beckhoff_cx9020 4.4.0.0 - 4.5.0.0
codesys/control_for_empc-a\/imx6_sl 4.4.0.0 - 4.5.0.0
codesys/control_for_iot2000_sl 4.4.0.0 - 4.5.0.0
codesys/control_for_linux_sl 4.4.0.0 - 4.5.0.0
codesys/control_for_pfc100_sl 4.4.0.0 - 4.5.0.0
codesys/control_for_pfc200_sl 4.4.0.0 - 4.5.0.0
codesys/control_for_raspberry_pi_sl 4.4.0.0 - 4.5.0.0
codesys/control_for_wago_touch_panels_600_sl 4.4.0.0 - 4.5.0.0
codesys/control_runtime_system_toolkit 3.5.17.0 - 3.5.18.0
Published Apr 07, 2022
Tracked Since Feb 18, 2026