CVE-2022-31805
published 2022-06-24CVE-2022-31805: In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.97%
58.1th percentile
In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| codesys | codesys_development_system | >= V2 < V2.3.9.69 | V2.3.9.69 |
| codesys | codesys_development_system | >= V3 < V3.5.18.30 | V3.5.18.30 |
| codesys | codesys_edge_gateway_for_windows | >= V3 < V3.5.18.30 | V3.5.18.30 |
| codesys | codesys_gateway | >= V3 < V3.5.18.30 | V3.5.18.30 |
| codesys | codesys_gateway_client | >= V2 < V2.3.9.38 | V2.3.9.38 |
| codesys | codesys_gateway_server | >= V2 < V2.3.9.38 | V2.3.9.38 |
| codesys | codesys_hmi | >= V3 < V3.5.18.30 | V3.5.18.30 |
| codesys | codesys_opc_da_server_sl | >= V3 < V3.5.18.30 | V3.5.18.30 |
| codesys | codesys_plchandler | >= V3 < V3.5.18.30 | V3.5.18.30 |
| codesys | codesys_plcwinnt | >= V2 < V2.4.7.57 | V2.4.7.57 |
| codesys | codesys_runtime_toolkit_32_bit_full | >= V2 < V2.4.7.57 | V2.4.7.57 |
| codesys | codesys_sp_realtime_nt | >= V2 < V2.3.7.30 | V2.3.7.30 |
| codesys | codesys_web_server | >= V1 < V1.1.9.23 | V1.1.9.23 |
| codesys | development_system | < 2.3.9.69 | 2.3.9.69 |
| codesys | edge_gateway | < 3.5.18.30 | 3.5.18.30 |
| codesys | gateway | < 2.3.9.38 | 2.3.9.38 |
| codesys | hmi_sl | < 3.5.18.30 | 3.5.18.30 |
| codesys | opc_server | < 3.5.18.30 | 3.5.18.30 |
| codesys | plchandler | < 3.5.18.30 | 3.5.18.30 |
| codesys | plcwinnt | < 2.4.7.57 | 2.4.7.57 |
| codesys | runtime_toolkit | < 2.4.7.57 | 2.4.7.57 |
| codesys | sp_realtime_nt | < 2.3.7.30 | 2.3.7.30 |
| codesys | web_server | < 1.1.9.23 | 1.1.9.23 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_oracle9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q837-53gv-8r7r: In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers un
ghsa_unreviewed·2022-06-25
CVE-2022-31805 [CRITICAL] CWE-523 GHSA-q837-53gv-8r7r: In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers un
In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
CISA ICS
CODESYS in Festo Automation Suite
cisa_ics·2026-03-17
CODESYS in Festo Automation Suite
ICS Advisory
##
CODESYS in Festo Automation Suite
Release DateMarch 17, 2026
Alert CodeICSA-26-076-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
3. TECHNICAL DETAILS
The following versions of CODESYS in Festo Automation Suite are affected:
- FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0) vers:all/*
- FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10) vers:all/*
- FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0) vers:all/*
- FESTO Software Festo Automation
Oracle
Oracle Oracle Communications Risk Matrix: Configuration Management Platform (Apache Struts) — CVE-2021-31805
vendor_oracle·2022-10-15·CVSS 9.8
CVE-2021-31805 [CRITICAL] Oracle Oracle Communications Risk Matrix: Configuration Management Platform (Apache Struts) — CVE-2021-31805
Oracle Oracle Communications Risk Matrix: Configuration Management Platform (Apache Struts) vulnerability
CVE: CVE-2021-31805
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Hospitality Applications Risk Matrix: Login (Apache Struts) — CVE-2021-31805
vendor_oracle·2022-07-15·CVSS 9.8
CVE-2021-31805 [CRITICAL] Oracle Oracle Hospitality Applications Risk Matrix: Login (Apache Struts) — CVE-2021-31805
Oracle Oracle Hospitality Applications Risk Matrix: Login (Apache Struts) vulnerability
CVE: CVE-2021-31805
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-06-24
Published