Input validation error in CODESYS products - CVE-2022-47378

 

Input validation error in CODESYS products - CVE-2022-47378

Published: January 31, 2024


Vulnerability identifier: #VU85945
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-47378
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in the CmpFiletransfer component. A remote user can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

CODESYS Control RTE (for Beckhoff CX)
CODESYS Control Win
CODESYS Control Runtime System Toolkit
CODESYS Safety SIL2 Runtime Toolkit
CODESYS Safety SIL2 PSP
CODESYS HMI
CODESYS Development System V3
CODESYS Control RTE
CODESYS Control for WAGO Touch Panels 600 SL
CODESYS Control for Raspberry Pi SL
CODESYS Control for PLCnext SL
CODESYS Control for PFC200 SL
CODESYS Control for PFC100 SL
CODESYS Control for Linux SL
CODESYS Control for IOT2000 SL
CODESYS Control for emPC-A/iMX6 SL
CODESYS Control for BeagleBone SL
LP30 Operator Panel
LP40 Operator Panel
LP50 Operator Panel
BM40 Operator Panel

How to mitigate CVE-2022-47378

Install updates from vendor's website.

CODESYS Control RTE (for Beckhoff CX) - update to 3.5.19.0
CODESYS Control Win - update to 3.5.19.0
CODESYS Control Runtime System Toolkit - update to 3.5.19.0
CODESYS Safety SIL2 Runtime Toolkit - update to 3.5.19.0
CODESYS Safety SIL2 PSP - update to 3.5.19.0
CODESYS HMI - update to 3.5.19.0
CODESYS Development System V3 - update to 3.5.19.0
CODESYS Control RTE - update to 3.5.19.0
CODESYS Control for WAGO Touch Panels 600 SL - update to 4.8.0.0
CODESYS Control for Raspberry Pi SL - update to 4.8.0.0
CODESYS Control for PLCnext SL - update to 4.8.0.0
CODESYS Control for PFC200 SL - update to 4.8.0.0
CODESYS Control for PFC100 SL - update to 4.8.0.0
CODESYS Control for Linux SL - update to 4.8.0.0
CODESYS Control for IOT2000 SL - update to 4.8.0.0
CODESYS Control for emPC-A/iMX6 SL - update to 4.8.0.0
CODESYS Control for BeagleBone SL - update to 4.8.0.0
LP30 Operator Panel - update to 3.5.19.0
LP40 Operator Panel - update to 3.5.19.0
LP50 Operator Panel - update to 3.5.19.0
BM40 Operator Panel - update to 3.5.19.0

External References

Related Security Bulletins