CVE-2022-47388: Codesys Control For Beaglebone Sl

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

Affected products

  • Codesys Control For Beaglebone Sl: before 4.8.0.0 (fixed in 4.8.0.0)
  • Codesys Control For Empc-a/imx6 Sl: before 4.8.0.0 (fixed in 4.8.0.0)
  • Codesys Control For IOT2000 Sl: before 4.8.0.0 (fixed in 4.8.0.0)
  • Codesys Control For Linux Sl: before 4.8.0.0 (fixed in 4.8.0.0)
  • Codesys Control For PFC100 Sl: before 4.8.0.0 (fixed in 4.8.0.0)
  • Codesys Control For PFC200 Sl: before 4.8.0.0 (fixed in 4.8.0.0)
  • Codesys Control For Plcnext Sl: before 4.8.0.0 (fixed in 4.8.0.0)
  • Codesys Control For Raspberry Pi Sl: before 4.8.0.0 (fixed in 4.8.0.0)
  • Codesys Control For Wago Touch Panels 600 Sl: before 4.8.0.0 (fixed in 4.8.0.0)
  • Codesys Control Rte (for Beckhoff Cx) Sl: before 3.5.19.0 (fixed in 3.5.19.0)
  • Codesys Control Rte (sl): before 3.5.19.0 (fixed in 3.5.19.0)
  • Codesys Control Runtime System Toolkit: before 3.5.19.0 (fixed in 3.5.19.0)
  • Codesys Control Win (sl): before 3.5.19.0 (fixed in 3.5.19.0)
  • Codesys Development System v3: before 3.5.19.0 (fixed in 3.5.19.0)
  • Codesys HMI (sl): before 3.5.19.0 (fixed in 3.5.19.0)
  • Codesys Safety SIL2 Psp: before 3.5.19.0 (fixed in 3.5.19.0)
  • Codesys Safety SIL2 Runtime Toolkit: before 3.5.19.0 (fixed in 3.5.19.0)

Published 2023-05-15. Last modified 2026-06-17.