cve/2022/CVE-2022-22516.md

22 lines
1.1 KiB
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2022-22516](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22516)
![](https://img.shields.io/static/v1?label=Product&message=CODESYS%20Control%20RTE%20(SL)%20&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=CODESYS%20Control%20RTE%20(for%20Beckhoff%20CX)%20SL%20&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=CODESYS%20Control%20Win%20(SL)%20&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=CODESYS%20Development%20System%20V3%20&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=V3.5.18.0%3C%20V3.5.18.0%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-732%20Incorrect%20Permission%20Assignment%20for%20Critical%20Resource&color=brighgreen)
### Description
The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/hfiref0x/KDU