CVE-2022-32143
Estado: ModificadaAlta (8.8)—
In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the PLC. All requests are processed on the controller only if no level 1 password is configured on the controller or if remote attacker has previously successfully authenticated himself to the controller. A successful Attack may lead to a denial of service, change of local files, or drain of confidential Information. User interaction is not required
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.19%
- Percentil entre todas las CVEs puntuadas: 67
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-552
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-32143",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "info@cert.vde.com",
"affectedData": [
{
"vendor": "CODESYS",
"product": "Runtime Toolkit",
"versions": [
{
"status": "affected",
"version": "V2",
"lessThan": "V2.4.7.57",
"versionType": "custom"
}
],
"platforms": [
"32 bit"
]
},
{
"vendor": "CODESYS",
"product": "PLCWinNT",
"versions": [
{
"status": "affected",
"version": "V2",
"lessThan": "V2.4.7.57",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-06-24T08:15:08.167",
"references": [
{
"url": "https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17139&token=ec67d15a433b61c77154166c20c78036540cacb0&download=",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "info@cert.vde.com"
},
{
"url": "https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17139&token=ec67d15a433b61c77154166c20c78036540cacb0&download=",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"description": [
{
"lang": "en",
"value": "CWE-552"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the PLC. All requests are processed on the controller only if no level 1 password is configured on the controller or if remote attacker has previously successfully authenticated himself to the controller. A successful Attack may lead to a denial of service, change of local files, or drain of confidential Information. User interaction is not required"
},
{
"lang": "es",
"value": "En Diversos productos CODESYS, la función de descarga y carga de archivos permite el acceso a archivos internos en el directorio de trabajo, por ejemplo, archivos de firmware del PLC. Todas las peticiones son procesadas en el controlador sólo si no presenta una contraseña de nivel 1 configurada en el controlador o si el atacante remoto ha sido autenticado previamente con éxito en el controlador. Un ataque con éxito puede conllevar a una denegación de servicio, la modificación de los archivos locales o un filtrado de información confidencial. No es requerida una interacción del usuario"
}
],
"lastModified": "2026-06-17T04:46:45.310",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:codesys:plcwinnt:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2B26FF87-3FCD-496E-97C5-A1E4F6AACCB1",
"versionEndExcluding": "2.4.7.57",
"versionStartIncluding": "2.0"
},
{
"criteria": "cpe:2.3:a:codesys:runtime_toolkit:*:*:*:*:*:*:x86:*",
"vulnerable": true,
"matchCriteriaId": "CF74E74E-4EF8-4C84-A9A1-612AB7FC88BA",
"versionEndExcluding": "2.4.7.57",
"versionStartIncluding": "2.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "info@cert.vde.com"
}