In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer real CODESYS Gateway password.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: CERTVDE
Published: 2022-06-24T07:46:09.625943Z
Updated: 2024-09-17T00:32:18.904Z
Reserved: 2022-05-30T00:00:00
Link: CVE-2022-31802
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-06-24T08:15:07.393
Modified: 2024-11-21T07:05:21.673
Link: CVE-2022-31802
Redhat
No data.