CVE-2022-4048 HIGH

CVE-2022-4048: CODESYS V3 prone to Inadequate Encryption Stregth

Vendor Codesys
Product CODESYS Development System V3
Weakness CWE-326 · Weak encryption
Published May 15, 2023
Last update January 23, 2025

CVSS base score

7.7/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

What the vulnerability does

01Description

Inadequate Encryption Strength in CODESYS Development System V3 versions prior to V3.5.18.40 allows an unauthenticated local attacker to access and manipulate code of the encrypted boot application.

Key dates

02Disclosure timeline

May 15, 2023 CVE published
January 23, 2025 Record updated