Vulnerability Intelligence Report
Insecure transmission of credentials
CVE-2022-31805
In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
No Active Exploit Signals
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:0.95%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-523 ↗CWE-523 Unprotected Transport of Credentials
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| CODESYS | CODESYS Development System | V2 < V2.3.9.69 (affected), V3 < V3.5.18.30 (affected) |
| CODESYS | CODESYS Gateway Client | V2 < V2.3.9.38 (affected) |
| CODESYS | CODESYS Gateway Server | V2 < V2.3.9.38 (affected) |
| CODESYS | CODESYS Web server | V1 < V1.1.9.23 (affected) |
| CODESYS | CODESYS SP Realtime NT | V2 < V2.3.7.30 (affected) |
| CODESYS | CODESYS PLCWinNT | V2 < V2.4.7.57 (affected) |
| CODESYS | CODESYS Runtime Toolkit 32 bit full | V2 < V2.4.7.57 (affected) |
| CODESYS | CODESYS Edge Gateway for Windows | V3 < V3.5.18.30 (affected) |
| CODESYS | CODESYS HMI (SL) | V3 < V3.5.18.30 (affected) |
| CODESYS | CODESYS OPC DA Server SL | V3 < V3.5.18.30 (affected) |
| CODESYS | CODESYS PLCHandler | V3 < V3.5.18.30 (affected) |
| CODESYS | CODESYS Gateway | V3 < V3.5.18.30 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.951%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | CERT@VDE · CERT · Germany |
| Reserved | 2022-05-30T00:00:00 |
| Published | 2022-06-24T07:46:15 |
| Patch Date | 2022-06-22 |
| Last Updated | 2024-09-16T18:55:26 |
Community Chatter & Buzz