First published: Mon Jul 11 2022(Updated: )
The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is visible to all authorized Microsoft Windows users of the system.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
CODESYS OPC DA Server | >=3.0.0<3.5.18.20 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1794 is a vulnerability in the CODESYS OPC DA Server prior to version V3.5.18.20 that allows plain text passwords to be stored in its configuration file.
CVE-2022-1794 allows authorized Microsoft Windows users to view the plain text passwords stored in the CODESYS OPC DA Server configuration file.
CVE-2022-1794 has a severity rating of 5.5 out of 10, which is considered medium.
To fix CVE-2022-1794, update the CODESYS OPC DA Server to version V3.5.18.20 or newer, where the vulnerability is patched.
No, Microsoft Windows is not affected by CVE-2022-1794 directly, but authorized users of Microsoft Windows can access the plain text passwords stored in the CODESYS OPC DA Server configuration file.