CVE-2022-47391

In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from invalid addresses leading to a denial of service.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_plcnext_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_\(for_beckhoff_cx\)_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_\(sl\):*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_runtime_system_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_win_\(sl\):*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:development_system_v3:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:hmi_\(sl\):*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:safety_sil2_psp:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:safety_sil2_runtime_toolkit:*:*:*:*:*:*:*:*

History

17 Jul 2025, 13:10

Type Values Removed Values Added
References (MISC) https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17555&token=212fc7e39bdd260cab6d6ca84333d42f50bcb3da&download= - Vendor Advisory () https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17555&token=212fc7e39bdd260cab6d6ca84333d42f50bcb3da&download= - Vendor Advisory
CPE cpe:2.3:a:codesys:development_system_v3:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:safety_sil2_psp:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:safety_sil2_runtime_toolkit:*:*:*:*:*:*:*:*
First Time Codesys development System V3
Codesys safety Sil2 Runtime Toolkit
Codesys safety Sil2 Psp

24 May 2023, 20:25

Type Values Removed Values Added
CPE cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_plcnext_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:hmi_\(sl\):*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_\(sl\):*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_win_\(sl\):*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_runtime_system_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_\(for_beckhoff_cx\)_sl:*:*:*:*:*:*:*:*
References (MISC) https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17555&token=212fc7e39bdd260cab6d6ca84333d42f50bcb3da&download= - (MISC) https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17555&token=212fc7e39bdd260cab6d6ca84333d42f50bcb3da&download= - Vendor Advisory
First Time Codesys control For Raspberry Pi Sl
Codesys
Codesys control Rte \(for Beckhoff Cx\) Sl
Codesys control For Plcnext Sl
Codesys control For Empc-a\/imx6 Sl
Codesys control Runtime System Toolkit
Codesys hmi \(sl\)
Codesys control For Wago Touch Panels 600 Sl
Codesys control For Pfc200 Sl
Codesys control For Iot2000 Sl
Codesys control For Linux Sl
Codesys control Rte \(sl\)
Codesys control For Pfc100 Sl
Codesys control For Beaglebone Sl
Codesys control Win \(sl\)

15 May 2023, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-15 10:15

Updated : 2025-07-17 13:10


NVD link : CVE-2022-47391

Mitre link : CVE-2022-47391


JSON object : View

Products Affected

codesys

  • control_for_plcnext_sl
  • control_for_wago_touch_panels_600_sl
  • control_runtime_system_toolkit
  • control_win_\(sl\)
  • control_rte_\(for_beckhoff_cx\)_sl
  • control_rte_\(sl\)
  • hmi_\(sl\)
  • control_for_empc-a\/imx6_sl
  • safety_sil2_runtime_toolkit
  • control_for_beaglebone_sl
  • control_for_linux_sl
  • safety_sil2_psp
  • control_for_pfc200_sl
  • control_for_raspberry_pi_sl
  • development_system_v3
  • control_for_iot2000_sl
  • control_for_pfc100_sl
CWE
CWE-20

Improper Input Validation