In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer real CODESYS Gateway password.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published: 2022-06-24T07:46:09.625943Z

Updated: 2024-09-17T00:32:18.904Z

Reserved: 2022-05-30T00:00:00

Link: CVE-2022-31802

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-06-24T08:15:07.393

Modified: 2022-07-01T13:34:15.277

Link: CVE-2022-31802

cve-icon Redhat

No data.