First published: Fri Jun 24 2022(Updated: )
In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the controller.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
CODESYS PLCWinNT | <2.4.7.57 | |
Codesys Runtime Toolkit | <2.4.7.57 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this CODESYS vulnerability is CVE-2022-31806.
The severity level of CVE-2022-31806 is critical, with a severity value of 9.8.
CODESYS V2 PLCWinNT and Runtime Toolkit 32 versions prior to V2.4.7.57 are affected by CVE-2022-31806.
CVE-2022-31806 allows unauthorized access to the controller when password protection is not enabled.
To mitigate CVE-2022-31806, ensure password protection is enabled by default or set a password at the controller.