CVE-2022-31802: Partial string comparison in CODESYS gateway server
In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer real CODESYS Gateway password.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-31802?
CVE-2022-31802 is a vulnerability in CODESYS Gateway Server V2 for versions prior to V2.3.9.38.
What is the severity of CVE-2022-31802?
CVE-2022-31802 has a severity rating of 9.8 (Critical).
How does CVE-2022-31802 affect CODESYS Gateway Server?
CVE-2022-31802 allows an attacker to perform authentication by specifying a small password that matches a part of the longer real CODESYS Gateway password.
Which versions of CODESYS Gateway Server are affected by CVE-2022-31802?
Versions prior to V2.3.9.38 of CODESYS Gateway Server are affected by CVE-2022-31802.
How can CVE-2022-31802 be fixed?
To fix CVE-2022-31802, update CODESYS Gateway Server to version V2.3.9.38 or later.