← Vulnerability feed

Vulnerability record · CVE-2022-32138 · published 24 June 2022

CVE-2022-32138: Codesys plcwinnt vulnerability

Codesys · Plcwinnt

In multiple CODESYS products, a remote attacker may craft a request which may cause an unexpected sign extension, resulting in a denial-of-service condition or memory overwrite.

8.8 CVSS 3.1 High EPSS 1.2% · top 33.3% CWE-194 · CWE-194
8.8CVSS 3.1 base score, v2 6.5
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In multiple CODESYS products, a remote attacker may craft a request which may cause an unexpected sign extension, resulting in a denial-of-service condition or memory overwrite.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-32138 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-31806Codesys plcwinnt insecure default initialization vulnerabilityIn CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no informatio…EPSS 1.2%8.8CVE-2023-6357Codesys control for beaglebone sl os command injection vulnerabilityA low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the…EPSS 0.96%8.8CVE-2022-4224Codesys control for beaglebone sl insecure default initialization vulnerabilityIn multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files…EPSS 0.88%8.8CVE-2022-32143Codesys plcwinnt vulnerabilityIn multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the P…EPSS 1.2%8.8CVE-2022-32137Codesys plcwinnt heap-based buffer overflow vulnerabilityIn multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause a heap-based buffer overflow, resulting in a deni…EPSS 1.4%8.8CVE-2019-9013Codesys control for beaglebone sl broken cryptographic algorithm vulnerabilityAn issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials bein…EPSS 0.28%8.1CVE-2022-32142Codesys plcwinnt vulnerabilityMultiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset…EPSS 1.1%8.1CVE-2022-1965Codesys plcwinnt vulnerabilityMultiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processe…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2022-32138), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.