Description
In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer real CODESYS Gateway password.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-53191 | In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer real CODESYS Gateway password. |
References
History
No history.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2024-09-17T00:32:18.904Z
Reserved: 2022-05-30T00:00:00.000Z
Link: CVE-2022-31802
No data.
Status : Modified
Published: 2022-06-24T08:15:07.393
Modified: 2024-11-21T07:05:21.673
Link: CVE-2022-31802
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD