CVE Published: 15/05/2023 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: CERTVDE |
Vendor: CODESYS |
Product: CODESYS Development System V3 Status : PUBLISHED
CVE-2022-4048 Description
Inadequate Encryption Strength in CODESYS Development System V3 versions prior to V3.5.18.40 allows an unauthenticated local attacker to access and manipulate code of the encrypted boot application.
Metrics
CVSS Version: 3.1 |
Base Score: 7.7 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N