CVE-2022-31803
published 2022-06-24CVE-2022-31803: In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all available TCP…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.03%
59.8th percentile
In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all available TCP connections and prevent legitimate users or clients from establishing a new connection to the CODESYS Gateway Server V2. Existing connections are not affected and therefore remain intact.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| codesys | codesys_gateway_server_v2 | >= V2 < V2.3.9.38 | V2.3.9.38 |
| codesys | gateway | >= 2.0 < 2.3.9.38 | 2.3.9.38 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9348-vpwc-ch78: In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all availa
ghsa_unreviewed·2022-06-25
CVE-2022-31803 [MEDIUM] CWE-400 GHSA-9348-vpwc-ch78: In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all availa
In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all available TCP connections and prevent legitimate users or clients from establishing a new connection to the CODESYS Gateway Server V2. Existing connections are not affected and therefore remain intact.
CISA ICS
FESTO CODESYS
cisa_ics·2025-07-01·CVSS 9.8
[CRITICAL] FESTO CODESYS
ICS Advisory
##
FESTO CODESYS
Release DateJuly 01, 2025
Alert CodeICSA-25-182-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: FESTO
- Equipment: CODESYS
- Vulnerabilities: Partial String Comparison, Uncontrolled Resource Consumption, Memory Allocation with Excessive Size Value
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to block legitimate user connections, crash the application, or authenticate without proper credentials.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
FESTO reports that the following products are affected:
- FESTO CODESYS Gatew
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-06-24
Published