CVE-2022-31805

In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CERTVDECNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
VendorProductVersion
codesysdevelopment_system
𝑥
< 2.3.9.69
codesysedge_gateway
𝑥
< 3.5.18.30
codesysgateway
𝑥
< 2.3.9.38
codesyshmi_sl
𝑥
< 3.5.18.30
codesysopc_server
𝑥
< 3.5.18.30
codesysplchandler
𝑥
< 3.5.18.30
codesysplcwinnt
𝑥
< 2.4.7.57
codesysruntime_toolkit
𝑥
< 2.4.7.57
codesyssp_realtime_nt
𝑥
< 2.3.7.30
codesysweb_server
𝑥
< 1.1.9.23
𝑥
= Vulnerable software versions