7.5

CVE-2022-31805

In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.

Data is provided by the National Vulnerability Database (NVD)
CodesysDevelopment System Version < 2.3.9.69
CodesysEdge Gateway SwPlatformwindows Version < 3.5.18.30
CodesysGateway Version < 2.3.9.38
CodesysHmi Sl Version < 3.5.18.30
CodesysOpc Server Version < 3.5.18.30
CodesysPlchandler Version < 3.5.18.30
CodesysPlcwinnt Version < 2.4.7.57
CodesysRuntime Toolkit HwPlatformx86 Version < 2.4.7.57
CodesysSp Realtime Nt Version < 2.3.7.30
CodesysWeb Server Version < 1.1.9.23
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.44% 0.624
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
info@cert.vde.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-523 Unprotected Transport of Credentials

Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.