CVE-2022-30792
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD (Secondary)
Description
In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected.
Affected (20)
Products: Codesys: Control For Beaglebone, Control For Empc A/imx6, Control For Iot2000 Sl, Control For Linux Sl, Control For Pfc100 Sl, Control For Pfc200 Sl, Control For Plcnext, Control For Raspberry Pi Sl, Control For Wago Touch Panels 600, Control Rte Sl, Control Rte Sl (for Beckhoff Cx), Control Runtime System Toolkit, Control Win, Development System, Edge Gateway, Embedded Target Visu Toolkit, Gateway, Hmi, Remote Target Visu Toolkit
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.5.0.0 | |
| Before 4.5.0.0 | |
| Before 4.6.0.0 | |
| Before 4.5.0.0 | |
| Before 4.5.0.0 | |
| Before 4.5.0.0 | |
| Before 4.6.0.0 | |
| Before 4.5.0.0 | |
| Before 4.5.0.0 | |
| Before 3.5.18.20 | |
| Before 3.5.18.20 | |
| Before 3.5.18.20 | |
| Before 3.5.18.20 | |
| Before 3.5.18.20 | |
| Before 4.5.0.0 | |
| Before 3.5.18.20 | |
| Before 3.5.18.20 | |
| Before 3.5.18.20 | |
| Before 3.5.18.20 |
References (2)
Source: info@cert.vde.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.