7.5
CVSSv3

CVE-2022-31805

Published: 24/06/2022 Updated: 09/05/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

codesys runtime toolkit

codesys plcwinnt

codesys plchandler

codesys opc server

codesys edge gateway

codesys hmi sl

codesys sp realtime nt

codesys web server

codesys gateway

codesys development system

Github Repositories

Commonly existing PLC Supply Chain Threats: Multiple critical vulnerabilities in Codesys Runtime Abstract We conducted an in-depth research on CODESYS V2 runtime and PLCs using this kernel (ABB AC500 PLCs) We found 11 vulnerabilities in CODESYS V2 runtime; 2 of all accepted vulnerabilities graded as critical, 7 as high risk, and 2 as medium risk These vulnerabilities a