Unrated severityNVD Advisory· Published Jun 24, 2022· Updated Sep 16, 2024
CODESYS runtime system prone to file deletion due to improper error handling
CVE-2022-1965
Description
Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required.
Affected products
2- CODESYS/PLCWinNTv5Range: V2
- Range: V2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- customers.codesys.com/index.phpmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.