CVE-2022-31806
Published: Jun 24, 2022
Modified: Sep 17, 2024
CVSS v3.1
9.8
Description
In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the controller.
| Vendor | Product | Versions |
|---|---|---|
CODESYS | CODESYS PLCWinNT | affected V2 - < V2.4.7.57 |
CODESYS | CODESYS Runtime Toolkit 32 bit full | affected V2 - < V2.4.7.57 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now