cbcvebase.
CVE-2022-31805
published 2022-06-24

CVE-2022-31805: In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.

Affected

23 ranges
VendorProductVersion rangeFixed in
codesyscodesys_development_system>= V2 < V2.3.9.69V2.3.9.69
codesyscodesys_development_system>= V3 < V3.5.18.30V3.5.18.30
codesyscodesys_edge_gateway_for_windows>= V3 < V3.5.18.30V3.5.18.30
codesyscodesys_gateway>= V3 < V3.5.18.30V3.5.18.30
codesyscodesys_gateway_client>= V2 < V2.3.9.38V2.3.9.38
codesyscodesys_gateway_server>= V2 < V2.3.9.38V2.3.9.38
codesyscodesys_hmi>= V3 < V3.5.18.30V3.5.18.30
codesyscodesys_opc_da_server_sl>= V3 < V3.5.18.30V3.5.18.30
codesyscodesys_plchandler>= V3 < V3.5.18.30V3.5.18.30
codesyscodesys_plcwinnt>= V2 < V2.4.7.57V2.4.7.57
codesyscodesys_runtime_toolkit_32_bit_full>= V2 < V2.4.7.57V2.4.7.57
codesyscodesys_sp_realtime_nt>= V2 < V2.3.7.30V2.3.7.30
codesyscodesys_web_server>= V1 < V1.1.9.23V1.1.9.23
codesysdevelopment_system< 2.3.9.692.3.9.69
codesysedge_gateway< 3.5.18.303.5.18.30
codesysgateway< 2.3.9.382.3.9.38
codesyshmi_sl< 3.5.18.303.5.18.30
codesysopc_server< 3.5.18.303.5.18.30
codesysplchandler< 3.5.18.303.5.18.30
codesysplcwinnt< 2.4.7.572.4.7.57
codesysruntime_toolkit< 2.4.7.572.4.7.57
codesyssp_realtime_nt< 2.3.7.302.3.7.30
codesysweb_server< 1.1.9.231.1.9.23