Free Webinar:

Incident responders TELL-ALL on May 16 with lessons learned from the frontlines of the OT cybersecurity battleground.

Skip to main content
Security Advisory

Digi TransPort Gateway Vulnerability

Insufficient Read and Write Protection to Logic and Runtime Data; Access to Sensitive System Files

Risk Information

Limited Threat

CVE ID

CVE-2022-4046

CVE-2022-4224

CVE-2023-29446

Vunerability Type

Insufficient Read and Write Protection to Logic and Runtime Data

Access to Sensitive System Files

CVSS3 Score

9.9

CVSSv3 Vector

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affecting

  • CODESYS Control for BeagleBone SL: All Versions
  • CODESYS Control for emPC-A/iMX6 SL: All Versions
  • CODESYS Control for IOT2000 SL: All Versions
  • CODESYS Control for Linux SL: All Versions
  • CODESYS Control for PFC100 SL: All Versions
  • CODESYS Control for PFC200 SL: All Versions
  • CODESYS Control for PLCnext SL: All Versions
  • CODESYS Control for Raspberry Pi SL: All Versions
  • CODESYS Control for WAGO Touch Panels 600 SL: All Versions
  • CODESYS Control RTE (for Beckhoff CX) SL: All Versions
  • CODESYS Control RTE (SL): All Versions
  • CODESYS Control Runtime System Toolkit: All Versions
  • CODESYS Control Win (SL): All Versions
  • CODESYS HMI (SL): All Versions
  • CODESYS Control RTE (SL): Prior to v3.5.19.0
  • CODESYS Control RTE (for Beckhoff CX) SL: Prior to v3.5.19.0
  • CODESYS Control Win (SL): Prior to v3.5.19.0
  • CODESYS Runtime Toolkit: Prior to v3.5.19.0
  • CODESYS Safety SIL2 Runtime Toolkit: Prior to v3.5.19.0
  • CODESYS Safety SIL2 PSP: Prior to v3.5.19.0
  • CODESYS HMI (SL): Prior to v3.5.19.0
  • CODESYS Development System V3: Prior to v3.5.19.0
  • CODESYS Control for BeagleBone SL: Prior to V4.8.0.0
  • CODESYS Control for emPC-A/iMX6 SL: Prior to V4.8.0.0
  • CODESYS Control for IOT2000 SL: Prior to V4.8.0.0
  • CODESYS Control for Linux SL: Prior to V4.8.0.0
  • CODESYS Control for PFC100 SL: Prior to V4.8.0.0
  • CODESYS Control for PFC200 SL: Prior to V4.8.0.0
  • CODESYS Control for PLCnext SL: Prior to V4.8.0.0
  • CODESYS Control for Raspberry Pi SL: Prior to V4.8.0.0
  • CODESYS Control for WAGO Touch Panels 600 SL: Prior to V4.8.0.0
  • Mitigation

    CODESYS released a patch to resolve: CVE-2022-4224

    04/11/2023