CVE-2022-31805

EUVD-2022-53194
In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CERTVDECNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
Affected Products (NVD)
VendorProductVersion
codesysdevelopment_system
𝑥
< 2.3.9.69
codesysedge_gateway
𝑥
< 3.5.18.30
codesysgateway
𝑥
< 2.3.9.38
codesyshmi_sl
𝑥
< 3.5.18.30
codesysopc_server
𝑥
< 3.5.18.30
codesysplchandler
𝑥
< 3.5.18.30
codesysplcwinnt
𝑥
< 2.4.7.57
codesysruntime_toolkit
𝑥
< 2.4.7.57
codesyssp_realtime_nt
𝑥
< 2.3.7.30
codesysweb_server
𝑥
< 1.1.9.23
𝑥
= Vulnerable software versions