CVE-2022-47382: Codesys Control For Beaglebone Sl
High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
Affected products
- Codesys Control For Beaglebone Sl: before 4.8.0.0 (fixed in 4.8.0.0)
- Codesys Control For Empc-a/imx6 Sl: before 4.8.0.0 (fixed in 4.8.0.0)
- Codesys Control For IOT2000 Sl: before 4.8.0.0 (fixed in 4.8.0.0)
- Codesys Control For Linux Sl: before 4.8.0.0 (fixed in 4.8.0.0)
- Codesys Control For PFC100 Sl: before 4.8.0.0 (fixed in 4.8.0.0)
- Codesys Control For PFC200 Sl: before 4.8.0.0 (fixed in 4.8.0.0)
- Codesys Control For Plcnext Sl: before 4.8.0.0 (fixed in 4.8.0.0)
- Codesys Control For Raspberry Pi Sl: before 4.8.0.0 (fixed in 4.8.0.0)
- Codesys Control For Wago Touch Panels 600 Sl: before 4.8.0.0 (fixed in 4.8.0.0)
- Codesys Control Rte (for Beckhoff Cx) Sl: before 3.5.19.0 (fixed in 3.5.19.0)
- Codesys Control Rte (sl): before 3.5.19.0 (fixed in 3.5.19.0)
- Codesys Control Runtime System Toolkit: before 3.5.19.0 (fixed in 3.5.19.0)
- Codesys Control Win (sl): before 3.5.19.0 (fixed in 3.5.19.0)
- Codesys Development System v3: before 3.5.19.0 (fixed in 3.5.19.0)
- Codesys HMI (sl): before 3.5.19.0 (fixed in 3.5.19.0)
- Codesys Safety SIL2 Psp: before 3.5.19.0 (fixed in 3.5.19.0)
- Codesys Safety SIL2 Runtime Toolkit: before 3.5.19.0 (fixed in 3.5.19.0)
Published 2023-05-15. Last modified 2026-06-17.