Vulnerability Intelligence Report
Insecure default settings in CODESYS Runtime Toolkit 32 bit full and CODESYS PLCWinNT
CVE-2022-31806
In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the controller.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:1.12%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| No affected products specified. | ||
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.118%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | CERT@VDE · CERT · Germany |
| Reserved | 2022-05-30T00:00:00 |
| Published | 2022-06-24T07:46:17 |
| Patch Date | 2022-06-23 |
| Last Updated | 2024-09-17T03:27:59 |
Community Chatter & Buzz