4.3

CVE-2022-31805

Insecure transmission of credentials

In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Codesys ≫ Development System Version < 2.3.9.69
Codesys ≫ Edge Gateway SwPlatform windows Version < 3.5.18.30
Codesys ≫ Gateway Version < 2.3.9.38
Codesys ≫ Hmi Sl Version < 3.5.18.30
Codesys ≫ Opc Server Version < 3.5.18.30
Codesys ≫ Plchandler Version < 3.5.18.30
Codesys ≫ Plcwinnt Version < 2.4.7.57
Codesys ≫ Runtime Toolkit HwPlatform x86 Version < 2.4.7.57
Codesys ≫ Sp Realtime Nt Version < 2.3.7.30
Codesys ≫ Web Server Version < 1.1.9.23
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.99% 0.595
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
info@cert.vde.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-523 Unprotected Transport of Credentials

Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.

https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17140&token=6aa2c5c4a8b83b8b09936fefed5b0b11f9d2cc6c&download=
Vendor Advisory