CVE-2022-32138CWE-194

CODESYS runtime system prone to denial of service due to Unexpected Sign Extension

High · published June 24, 2022

CVSS v3.1
8.8
EPSS
1%
Percentile
64.9
In the wild
Unconfirmed
What it is

In multiple CODESYS products, a remote attacker may craft a request which may cause an unexpected sign extension, resulting in a denial-of-service condition or memory overwrite.

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.01156 · 64.9th percentile
Weakness
CWE-194 · Unexpected Sign Extension
Published
2022-06-24T07:46Z
EPSS history
Timeline
  • 24 JUN 07:46Z
    CODESYS runtime system prone to denial of service due to Unexpected Sign Extension
    cvelistv5