9.8
CVSSv3

CVE-2022-31806

Published: 24/06/2022 Updated: 07/07/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the controller.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

codesys runtime toolkit

codesys plcwinnt

Github Repositories

Commonly existing PLC Supply Chain Threats: Multiple critical vulnerabilities in Codesys Runtime Abstract We conducted an in-depth research on CODESYS V2 runtime and PLCs using this kernel (ABB AC500 PLCs) We found 11 vulnerabilities in CODESYS V2 runtime; 2 of all accepted vulnerabilities graded as critical, 7 as high risk, and 2 as medium risk These vulnerabilities a