CVE-2022-1794

The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is visible to all authorized Microsoft Windows users of the system.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:codesys:opc_da_server:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:41

Type Values Removed Values Added
References () https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17129&token=1c1485c4a700c04f2069699f5be7558d276ca117&download= - Vendor Advisory () https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17129&token=1c1485c4a700c04f2069699f5be7558d276ca117&download= - Vendor Advisory

27 Jun 2023, 15:56

Type Values Removed Values Added
CWE CWE-256 CWE-522

Information

Published : 2022-07-11 11:15

Updated : 2024-11-21 06:41


NVD link : CVE-2022-1794

Mitre link : CVE-2022-1794

CVE.ORG link : CVE-2022-1794


JSON object : View

Products Affected

codesys

  • opc_da_server

microsoft

  • windows
CWE
CWE-256

Plaintext Storage of a Password

CWE-522

Insufficiently Protected Credentials