CVE-2022-1989: CODESYS Visualization vulnerable to user enumeration
Published Aug 23, 2022
·Updated
All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to information exposure allowing a remote, unauthenticated attacker to enumerate valid users.
Affected Software
1 affected component
CODESYS Visualization>=4.0.0.0<4.2.0.0
Event History
Aug 23, 2022
CVE Published
via MITRE·09:55 AM
Data Sourced
via MITRE·09:55 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-1989.
2
What is the severity rating of CVE-2022-1989?
CVE-2022-1989 has a severity rating of 5.3 (medium).
3
What is the affected software for CVE-2022-1989?
The affected software for CVE-2022-1989 is CODESYS Visualization versions before V4.2.0.0.
4
How does CVE-2022-1989 impact the affected software?
CVE-2022-1989 exposes login dialog information, allowing a remote, unauthenticated attacker to enumerate valid users.
5
Is there a fix available for CVE-2022-1989?
Yes, upgrading to CODESYS Visualization version V4.2.0.0 or later fixes CVE-2022-1989.