CVE Database
/

CVE-2022-31805

Back to search

CVE-2022-31805

Published: Jun 24, 2022

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.1

7.5

HIGH

Description

In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.

VendorProductVersions

CODESYS

CODESYS Development System

affected
V2 - < V2.3.9.69
affected
V3 - < V3.5.18.30

CODESYS

CODESYS Gateway Client

affected
V2 - < V2.3.9.38

CODESYS

CODESYS Gateway Server

affected
V2 - < V2.3.9.38

CODESYS

CODESYS Web server

affected
V1 - < V1.1.9.23

CODESYS

CODESYS SP Realtime NT

affected
V2 - < V2.3.7.30

CODESYS

CODESYS PLCWinNT

affected
V2 - < V2.4.7.57

CODESYS

CODESYS Runtime Toolkit 32 bit full

affected
V2 - < V2.4.7.57

CODESYS

CODESYS Edge Gateway for Windows

affected
V3 - < V3.5.18.30

CODESYS

CODESYS HMI (SL)

affected
V3 - < V3.5.18.30

CODESYS

CODESYS OPC DA Server SL

affected
V3 - < V3.5.18.30

CODESYS

CODESYS PLCHandler

affected
V3 - < V3.5.18.30

CODESYS

CODESYS Gateway

affected
V3 - < V3.5.18.30

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now