CVE-2022-31805

In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:codesys:development_system:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:edge_gateway:*:*:*:*:*:windows:*:*
cpe:2.3:a:codesys:gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:hmi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:opc_server:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:plchandler:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:plcwinnt:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:runtime_toolkit:*:*:*:*:*:*:x86:*
cpe:2.3:a:codesys:sp_realtime_nt:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:web_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-06-24 08:15

Updated : 2023-05-09 13:15


NVD link : CVE-2022-31805

Mitre link : CVE-2022-31805

CVE.ORG link : CVE-2022-31805


JSON object : View

Products Affected

codesys

  • edge_gateway
  • plchandler
  • plcwinnt
  • hmi_sl
  • runtime_toolkit
  • development_system
  • opc_server
  • gateway
  • sp_realtime_nt
  • web_server
CWE
CWE-523

Unprotected Transport of Credentials