First published: Fri Jun 24 2022(Updated: )
In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer real CODESYS Gateway password.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
CODESYS Gateway | >=2.0<2.3.9.38 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31802 is a vulnerability in CODESYS Gateway Server V2 for versions prior to V2.3.9.38.
CVE-2022-31802 has a severity rating of 9.8 (Critical).
CVE-2022-31802 allows an attacker to perform authentication by specifying a small password that matches a part of the longer real CODESYS Gateway password.
Versions prior to V2.3.9.38 of CODESYS Gateway Server are affected by CVE-2022-31802.
To fix CVE-2022-31802, update CODESYS Gateway Server to version V2.3.9.38 or later.