CVE-2022-31803: CODESYS Gateway Server V2 prone to Denial of Service Attack
In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all available TCP connections and prevent legitimate users or clients from establishing a new connection to the CODESYS Gateway Server V2. Existing connections are not affected and therefore remain intact.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-31803?
CVE-2022-31803 is a vulnerability in CODESYS Gateway Server V2 that allows an unauthenticated attacker to consume all available TCP connections and prevent legitimate users or clients from establishing a new connection to the server.
What is the severity of CVE-2022-31803?
CVE-2022-31803 has a severity rating of 5.3, which is considered medium.
How does CVE-2022-31803 affect CODESYS Gateway Server?
CVE-2022-31803 affects CODESYS Gateway Server V2 by allowing an attacker to consume all available TCP connections, thereby preventing new connections from legitimate users or clients.
Who is affected by CVE-2022-31803?
Users of CODESYS Gateway Server V2 versions 2.0 to 2.3.9.38 are affected by CVE-2022-31803.
How can I mitigate CVE-2022-31803?
To mitigate CVE-2022-31803, it is recommended to update CODESYS Gateway Server V2 to a version that includes a fix for the vulnerability.