CVE Vulnerabilities

CVE-2022-31805

Unprotected Transport of Credentials

Published: Jun 24, 2022 | Modified: May 09, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.

Weakness

Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.

Affected Software

Name Vendor Start Version End Version
Development_system Codesys * 2.3.9.69 (excluding)
Edge_gateway Codesys * 3.5.18.30 (excluding)
Gateway Codesys * 2.3.9.38 (excluding)
Hmi_sl Codesys * 3.5.18.30 (excluding)
Opc_server Codesys * 3.5.18.30 (excluding)
Plchandler Codesys * 3.5.18.30 (excluding)
Plcwinnt Codesys * 2.4.7.57 (excluding)
Runtime_toolkit Codesys * 2.4.7.57 (excluding)
Sp_realtime_nt Codesys * 2.3.7.30 (excluding)
Web_server Codesys * 1.1.9.23 (excluding)

Potential Mitigations

References