V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2022-31805
CVE
High

In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and…

CVSS
7.5
High
EPSS
0.01
p54
Published
2022-01-01
Updated
2022-01-01
Description

In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.

Tags · CWE
Pre-auth
CWE-523
CAPEC-102
Affected products
Development_system < 2.3.9.69Edge_gateway < 3.5.18.30Gateway < 2.3.9.38Hmi_sl < 3.5.18.30Opc_server < 3.5.18.30Plchandler < 3.5.18.30Plcwinnt < 2.4.7.57Runtime_toolkit < 2.4.7.57Sp_realtime_nt < 2.3.7.30Web_server < 1.1.9.23
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Timeline
2022-01-01
Published
2022-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.009 · p54
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
development_system*Tracked
edge_gateway*Tracked
gateway*Tracked
hmi_sl*Tracked
opc_server*Tracked
plchandler*Tracked
plcwinnt*Tracked
runtime_toolkit*Tracked
sp_realtime_nt*Tracked
web_server*Tracked
Source databases
CVE