In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
2022-06-24T08:15:07.590
2024-11-21T07:05:22.057
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:M/Au:N/C:P/I:N/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | codesys | development_system | < 2.3.9.69 | Yes |
Application | codesys | edge_gateway | < 3.5.18.30 | Yes |
Application | codesys | gateway | < 2.3.9.38 | Yes |
Application | codesys | hmi_sl | < 3.5.18.30 | Yes |
Application | codesys | opc_server | < 3.5.18.30 | Yes |
Application | codesys | plchandler | < 3.5.18.30 | Yes |
Application | codesys | plcwinnt | < 2.4.7.57 | Yes |
Application | codesys | runtime_toolkit | < 2.4.7.57 | Yes |
Application | codesys | sp_realtime_nt | < 2.3.7.30 | Yes |
Application | codesys | web_server | < 1.1.9.23 | Yes |