CVE-2022-31805

In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:codesys:development_system:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:edge_gateway:*:*:*:*:*:windows:*:*
cpe:2.3:a:codesys:gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:hmi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:opc_server:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:plchandler:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:plcwinnt:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:runtime_toolkit:*:*:*:*:*:*:x86:*
cpe:2.3:a:codesys:sp_realtime_nt:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:web_server:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:05

Type Values Removed Values Added
References () https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17140&token=6aa2c5c4a8b83b8b09936fefed5b0b11f9d2cc6c&download= - Vendor Advisory () https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17140&token=6aa2c5c4a8b83b8b09936fefed5b0b11f9d2cc6c&download= - Vendor Advisory

16 Sep 2024, 19:16

Type Values Removed Values Added
Summary (en) In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected. (en) In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.

Information

Published : 2022-06-24 08:15

Updated : 2024-11-21 07:05


NVD link : CVE-2022-31805

Mitre link : CVE-2022-31805

CVE.ORG link : CVE-2022-31805


JSON object : View

Products Affected

codesys

  • plcwinnt
  • web_server
  • edge_gateway
  • opc_server
  • plchandler
  • hmi_sl
  • sp_realtime_nt
  • development_system
  • runtime_toolkit
  • gateway
CWE
CWE-523

Unprotected Transport of Credentials